Skip to content
Noroxi

bbPress records

6 published records for vendor bbpress.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
16.7%
Median publish → KEV
No record has entered KEV

Records by year

  1. 20

Bar: total · dark part: CISA KEV.

All records

6 records
  • An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.

    CriticalCVSS 9.8Proof of conceptEPSS 44%

    bbpress · bbpressMay 28, 2020

  • CVE-2007-3244
    31Monitor

    SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrar

    HighCVSS 7.5No exploitEPSS 2%

    bbpress · bbpressJun 14, 2007

  • CVE-2011-1150
    24Monitor

    bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    bbpress · bbpressFeb 5, 2020

  • CVE-2011-3710
    20Monitor

    bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pa

    MediumCVSS 5.0No exploitEPSS 2%

    bbpress · bbpressSep 23, 2011

  • The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/e

    MediumCVSS 4.8No exploitEPSS 2%

    bbpress · bbpressMay 26, 2020

  • CVE-2007-3243
    18Monitor

    Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 4.3Proof of conceptEPSS 2%

    bbpress · bbpressJun 14, 2007