Записи SimpleMachines
31 опубликованных записей вендора simplemachines.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-20 Improper Input Validation5
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-99 Improper Control of Resource Identifiers ('Resource Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
31 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2011-1127Эксплойта нет | SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote asimplemachines · smf · CWE-264 | Критическая10,0 | — | 2,2 % | 20 июн. 2011 г. |
40В плане | CVE-2005-4891Proof of concept | Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary Ssimplemachines · simple machine forum · CWE-89 | Критическая9,8 | — | 1,7 % | 15 янв. 2020 г. |
39Наблюдать | CVE-2016-5726Эксплойта нет | Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP cosimplemachines · simple machines forum · CWE-94 | Критическая9,8 | — | 1,6 % | 9 февр. 2017 г. |
39Наблюдать | CVE-2019-11574Эксплойта нет | An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17.simplemachines · simple machine forum · CWE-918 | Критическая9,8 | — | 1,5 % | 20 мар. 2020 г. |
39Наблюдать | CVE-2018-10305Эксплойта нет | The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users varsimplemachines · simple machines forum | Критическая9,8 | — | 1,2 % | 23 апр. 2018 г. |
36Наблюдать | CVE-2013-7466Эксплойта нет | Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversimplemachines · simple machines forum · CWE-22 | Высокая8,8 | — | 4,0 % | 7 мар. 2019 г. |
35Наблюдать | CVE-2016-5727Эксплойта нет | LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP cosimplemachines · simple machines forum · CWE-94 | Высокая8,8 | — | 1,5 % | 9 февр. 2017 г. |
33Наблюдать | CVE-2013-7468Эксплойта нет | Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.simplemachines · simple machines forum · CWE-94 | Высокая8,1 | — | 1,7 % | 7 мар. 2019 г. |
32Наблюдать | CVE-2008-6971Proof of concept | The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes simplemachines · smf · CWE-255 | Высокая7,5 | — | 7,1 % | 13 авг. 2009 г. |
31Наблюдать | CVE-2022-26982Proof of concept | SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php codsimplemachines · simple machines forum · CWE-94 | Высокая7,2 | — | 9,2 % | 5 апр. 2022 г. |
30Наблюдать | CVE-2011-1128Эксплойта нет | The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invsimplemachines · smf · CWE-310 | Высокая7,5 | — | 1,6 % | 20 июн. 2011 г. |
30Наблюдать | CVE-2013-7235Эксплойта нет | Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space chasimplemachines · simple machines forum · CWE-20 | Высокая7,5 | — | 1,5 % | 29 апр. 2014 г. |
30Наблюдать | CVE-2013-7236Эксплойта нет | Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph characsimplemachines · simple machines forum · CWE-20 | Высокая7,5 | — | 1,5 % | 29 апр. 2014 г. |
30Наблюдать | CVE-2011-3615Эксплойта нет | Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute asimplemachines · smf · CWE-89 | Высокая7,5 | — | 1,1 % | 24 окт. 2011 г. |
30Наблюдать | CVE-2011-1130Эксплойта нет | Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote simplemachines · smf · CWE-20 | Высокая7,5 | — | 1,1 % | 20 июн. 2011 г. |
29Наблюдать | CVE-2009-5068Proof of concept | There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3.simplemachines · simple machines forum · CWE-312 | Высокая7,2 | — | 1,7 % | 15 янв. 2020 г. |
27Наблюдать | CVE-2011-4173Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authensimplemachines · smf · CWE-352 | Средняя6,8 | — | 0,6 % | 24 окт. 2011 г. |
26Наблюдать | CVE-2019-12490Эксплойта нет | An issue was discovered in Simple Machines Forum (SMF) before 2.0.16.simplemachines · simple machines forum | Средняя6,5 | — | 1,3 % | 22 янв. 2020 г. |
24Наблюдать | CVE-2013-4395Эксплойта нет | Simple Machines Forum (SMF) through 2.0.5 has XSSsimplemachines · simple machines forum · CWE-79 | Средняя6,1 | — | 1,0 % | 12 февр. 2020 г. |
24Наблюдать | CVE-2013-7467Эксплойта нет | Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.simplemachines · simple machines forum · CWE-79 | Средняя6,1 | — | 0,8 % | 7 мар. 2019 г. |
24Наблюдать | CVE-2025-67163Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML simplemachines · simple machines forum · CWE-20 | Средняя6,1 | — | 0,3 % | 18 дек. 2025 г. |
21Наблюдать | CVE-2024-7438Эксплойта нет | SimpleMachines SMF User Alert Read Status index.php resource injectionsimplemachines · simple machines forum · CWE-99 | Средняя5,3 | — | 0,5 % | 3 авг. 2024 г. |
21Наблюдать | CVE-2024-7437Эксплойта нет | SimpleMachines SMF Delete User index.php resource injectionsimplemachines · simple machines forum · CWE-99 | Средняя5,3 | — | 0,4 % | 3 авг. 2024 г. |
20Наблюдать | CVE-2013-0192Proof of concept | File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.simplemachines · simple machines forum · CWE-200 | Средняя4,9 | — | 3,8 % | 7 февр. 2020 г. |
20Наблюдать | CVE-2011-1131Эксплойта нет | The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a simplemachines · smf · CWE-200 | Средняя5,0 | — | 1,2 % | 20 июн. 2011 г. |
- CVE-2011-112741В плане
SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote a
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %simplemachines · smf20 июн. 2011 г.
- CVE-2005-489140В плане
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary S
КритическаяCVSS 9,8Proof of conceptEPSS 2 %simplemachines · simple machine forum15 янв. 2020 г.
- CVE-2016-572639Наблюдать
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP co
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %simplemachines · simple machines forum9 февр. 2017 г.
- CVE-2019-1157439Наблюдать
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %simplemachines · simple machine forum20 мар. 2020 г.
- CVE-2018-1030539Наблюдать
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users var
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %simplemachines · simple machines forum23 апр. 2018 г.
- CVE-2013-746636Наблюдать
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traver
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %simplemachines · simple machines forum7 мар. 2019 г.
- CVE-2016-572735Наблюдать
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP co
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %simplemachines · simple machines forum9 февр. 2017 г.
- CVE-2013-746833Наблюдать
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %simplemachines · simple machines forum7 мар. 2019 г.
- CVE-2008-697132Наблюдать
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %simplemachines · smf13 авг. 2009 г.
- CVE-2022-2698231Наблюдать
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php cod
ВысокаяCVSS 7,2Proof of conceptEPSS 9 %simplemachines · simple machines forum5 апр. 2022 г.
- CVE-2011-112830Наблюдать
The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle inv
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %simplemachines · smf20 июн. 2011 г.
- CVE-2013-723530Наблюдать
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space cha
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %simplemachines · simple machines forum29 апр. 2014 г.
- CVE-2013-723630Наблюдать
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph charac
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %simplemachines · simple machines forum29 апр. 2014 г.
- CVE-2011-361530Наблюдать
Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %simplemachines · smf24 окт. 2011 г.
- CVE-2011-113030Наблюдать
Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %simplemachines · smf20 июн. 2011 г.
- CVE-2009-506829Наблюдать
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3.
ВысокаяCVSS 7,2Proof of conceptEPSS 2 %simplemachines · simple machines forum15 янв. 2020 г.
- CVE-2011-417327Наблюдать
Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authen
СредняяCVSS 6,8Эксплойта нетEPSS 1 %simplemachines · smf24 окт. 2011 г.
- CVE-2019-1249026Наблюдать
An issue was discovered in Simple Machines Forum (SMF) before 2.0.16.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %simplemachines · simple machines forum22 янв. 2020 г.
- CVE-2013-439524Наблюдать
Simple Machines Forum (SMF) through 2.0.5 has XSS
СредняяCVSS 6,1Эксплойта нетEPSS 1 %simplemachines · simple machines forum12 февр. 2020 г.
- CVE-2013-746724Наблюдать
Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %simplemachines · simple machines forum7 мар. 2019 г.
- CVE-2025-6716324Наблюдать
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML
СредняяCVSS 6,1Эксплойта нетEPSS 0 %simplemachines · simple machines forum18 дек. 2025 г.
- CVE-2024-743821Наблюдать
SimpleMachines SMF User Alert Read Status index.php resource injection
СредняяCVSS 5,3Эксплойта нетEPSS 0 %simplemachines · simple machines forum3 авг. 2024 г.
- CVE-2024-743721Наблюдать
SimpleMachines SMF Delete User index.php resource injection
СредняяCVSS 5,3Эксплойта нетEPSS 0 %simplemachines · simple machines forum3 авг. 2024 г.
- CVE-2013-019220Наблюдать
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
СредняяCVSS 4,9Proof of conceptEPSS 4 %simplemachines · simple machines forum7 февр. 2020 г.
- CVE-2011-113120Наблюдать
The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a
СредняяCVSS 5,0Эксплойта нетEPSS 1 %simplemachines · smf20 июн. 2011 г.