SimpleMachines kayıtları
simplemachines üreticisine ait 31 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-20 Improper Input Validation5
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-99 Improper Control of Resource Identifiers ('Resource Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
31 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2011-1127İstismar yok | SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote asimplemachines · smf · CWE-264 | Kritik10,0 | — | %2,2 | 20 Haz 2011 |
40Planlayın | CVE-2005-4891Kavram kanıtı | Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary Ssimplemachines · simple machine forum · CWE-89 | Kritik9,8 | — | %1,7 | 15 Oca 2020 |
39İzleyin | CVE-2016-5726İstismar yok | Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP cosimplemachines · simple machines forum · CWE-94 | Kritik9,8 | — | %1,6 | 9 Şub 2017 |
39İzleyin | CVE-2019-11574İstismar yok | An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17.simplemachines · simple machine forum · CWE-918 | Kritik9,8 | — | %1,5 | 20 Mar 2020 |
39İzleyin | CVE-2018-10305İstismar yok | The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users varsimplemachines · simple machines forum | Kritik9,8 | — | %1,2 | 23 Nis 2018 |
36İzleyin | CVE-2013-7466İstismar yok | Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversimplemachines · simple machines forum · CWE-22 | Yüksek8,8 | — | %4,0 | 7 Mar 2019 |
35İzleyin | CVE-2016-5727İstismar yok | LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP cosimplemachines · simple machines forum · CWE-94 | Yüksek8,8 | — | %1,5 | 9 Şub 2017 |
33İzleyin | CVE-2013-7468İstismar yok | Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.simplemachines · simple machines forum · CWE-94 | Yüksek8,1 | — | %1,7 | 7 Mar 2019 |
32İzleyin | CVE-2008-6971Kavram kanıtı | The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes simplemachines · smf · CWE-255 | Yüksek7,5 | — | %7,1 | 13 Ağu 2009 |
31İzleyin | CVE-2022-26982Kavram kanıtı | SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php codsimplemachines · simple machines forum · CWE-94 | Yüksek7,2 | — | %9,2 | 5 Nis 2022 |
30İzleyin | CVE-2011-1128İstismar yok | The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invsimplemachines · smf · CWE-310 | Yüksek7,5 | — | %1,6 | 20 Haz 2011 |
30İzleyin | CVE-2013-7235İstismar yok | Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space chasimplemachines · simple machines forum · CWE-20 | Yüksek7,5 | — | %1,5 | 29 Nis 2014 |
30İzleyin | CVE-2013-7236İstismar yok | Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph characsimplemachines · simple machines forum · CWE-20 | Yüksek7,5 | — | %1,5 | 29 Nis 2014 |
30İzleyin | CVE-2011-3615İstismar yok | Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute asimplemachines · smf · CWE-89 | Yüksek7,5 | — | %1,1 | 24 Eki 2011 |
30İzleyin | CVE-2011-1130İstismar yok | Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote simplemachines · smf · CWE-20 | Yüksek7,5 | — | %1,1 | 20 Haz 2011 |
29İzleyin | CVE-2009-5068Kavram kanıtı | There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3.simplemachines · simple machines forum · CWE-312 | Yüksek7,2 | — | %1,7 | 15 Oca 2020 |
27İzleyin | CVE-2011-4173İstismar yok | Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authensimplemachines · smf · CWE-352 | Orta6,8 | — | %0,6 | 24 Eki 2011 |
26İzleyin | CVE-2019-12490İstismar yok | An issue was discovered in Simple Machines Forum (SMF) before 2.0.16.simplemachines · simple machines forum | Orta6,5 | — | %1,3 | 22 Oca 2020 |
24İzleyin | CVE-2013-4395İstismar yok | Simple Machines Forum (SMF) through 2.0.5 has XSSsimplemachines · simple machines forum · CWE-79 | Orta6,1 | — | %1,0 | 12 Şub 2020 |
24İzleyin | CVE-2013-7467İstismar yok | Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.simplemachines · simple machines forum · CWE-79 | Orta6,1 | — | %0,8 | 7 Mar 2019 |
24İzleyin | CVE-2025-67163İstismar yok | A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML simplemachines · simple machines forum · CWE-20 | Orta6,1 | — | %0,3 | 18 Ara 2025 |
21İzleyin | CVE-2024-7438İstismar yok | SimpleMachines SMF User Alert Read Status index.php resource injectionsimplemachines · simple machines forum · CWE-99 | Orta5,3 | — | %0,5 | 3 Ağu 2024 |
21İzleyin | CVE-2024-7437İstismar yok | SimpleMachines SMF Delete User index.php resource injectionsimplemachines · simple machines forum · CWE-99 | Orta5,3 | — | %0,4 | 3 Ağu 2024 |
20İzleyin | CVE-2013-0192Kavram kanıtı | File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.simplemachines · simple machines forum · CWE-200 | Orta4,9 | — | %3,8 | 7 Şub 2020 |
20İzleyin | CVE-2011-1131İstismar yok | The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a simplemachines · smf · CWE-200 | Orta5,0 | — | %1,2 | 20 Haz 2011 |
- CVE-2011-112741Planlayın
SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote a
KritikCVSS 10,0İstismar yokEPSS %2simplemachines · smf20 Haz 2011
- CVE-2005-489140Planlayın
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary S
KritikCVSS 9,8Kavram kanıtıEPSS %2simplemachines · simple machine forum15 Oca 2020
- CVE-2016-572639İzleyin
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP co
KritikCVSS 9,8İstismar yokEPSS %2simplemachines · simple machines forum9 Şub 2017
- CVE-2019-1157439İzleyin
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17.
KritikCVSS 9,8İstismar yokEPSS %1simplemachines · simple machine forum20 Mar 2020
- CVE-2018-1030539İzleyin
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users var
KritikCVSS 9,8İstismar yokEPSS %1simplemachines · simple machines forum23 Nis 2018
- CVE-2013-746636İzleyin
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traver
YüksekCVSS 8,8İstismar yokEPSS %4simplemachines · simple machines forum7 Mar 2019
- CVE-2016-572735İzleyin
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP co
YüksekCVSS 8,8İstismar yokEPSS %2simplemachines · simple machines forum9 Şub 2017
- CVE-2013-746833İzleyin
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.
YüksekCVSS 8,1İstismar yokEPSS %2simplemachines · simple machines forum7 Mar 2019
- CVE-2008-697132İzleyin
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes
YüksekCVSS 7,5Kavram kanıtıEPSS %7simplemachines · smf13 Ağu 2009
- CVE-2022-2698231İzleyin
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php cod
YüksekCVSS 7,2Kavram kanıtıEPSS %9simplemachines · simple machines forum5 Nis 2022
- CVE-2011-112830İzleyin
The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle inv
YüksekCVSS 7,5İstismar yokEPSS %2simplemachines · smf20 Haz 2011
- CVE-2013-723530İzleyin
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space cha
YüksekCVSS 7,5İstismar yokEPSS %2simplemachines · simple machines forum29 Nis 2014
- CVE-2013-723630İzleyin
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph charac
YüksekCVSS 7,5İstismar yokEPSS %2simplemachines · simple machines forum29 Nis 2014
- CVE-2011-361530İzleyin
Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute a
YüksekCVSS 7,5İstismar yokEPSS %1simplemachines · smf24 Eki 2011
- CVE-2011-113030İzleyin
Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote
YüksekCVSS 7,5İstismar yokEPSS %1simplemachines · smf20 Haz 2011
- CVE-2009-506829İzleyin
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3.
YüksekCVSS 7,2Kavram kanıtıEPSS %2simplemachines · simple machines forum15 Oca 2020
- CVE-2011-417327İzleyin
Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authen
OrtaCVSS 6,8İstismar yokEPSS %1simplemachines · smf24 Eki 2011
- CVE-2019-1249026İzleyin
An issue was discovered in Simple Machines Forum (SMF) before 2.0.16.
OrtaCVSS 6,5İstismar yokEPSS %1simplemachines · simple machines forum22 Oca 2020
- CVE-2013-439524İzleyin
Simple Machines Forum (SMF) through 2.0.5 has XSS
OrtaCVSS 6,1İstismar yokEPSS %1simplemachines · simple machines forum12 Şub 2020
- CVE-2013-746724İzleyin
Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.
OrtaCVSS 6,1İstismar yokEPSS %1simplemachines · simple machines forum7 Mar 2019
- CVE-2025-6716324İzleyin
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML
OrtaCVSS 6,1İstismar yokEPSS %0simplemachines · simple machines forum18 Ara 2025
- CVE-2024-743821İzleyin
SimpleMachines SMF User Alert Read Status index.php resource injection
OrtaCVSS 5,3İstismar yokEPSS %0simplemachines · simple machines forum3 Ağu 2024
- CVE-2024-743721İzleyin
SimpleMachines SMF Delete User index.php resource injection
OrtaCVSS 5,3İstismar yokEPSS %0simplemachines · simple machines forum3 Ağu 2024
- CVE-2013-019220İzleyin
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
OrtaCVSS 4,9Kavram kanıtıEPSS %4simplemachines · simple machines forum7 Şub 2020
- CVE-2011-113120İzleyin
The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a
OrtaCVSS 5,0İstismar yokEPSS %1simplemachines · smf20 Haz 2011