Bbpress
Bbpress: vulnerabilities and CVEs
Bbpress has 9 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs9
Last 12 months2
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62137 | Medium (5.3) | 0.31% | — | Sep 11, 2026 | Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. |
| CVE-2026-74010 | Medium (5.3) | 0.31% | — | Aug 31, 2026 | Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14. |
| CVE-2025-1435 | Medium (6.3) | 0.20% | — | Mar 5, 2025 | The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11. This is due to missing or incorrect nonce validation on the bbp_user_add_role_on_register()… |
| CVE-2020-13693 | Critical (9.8) | 44% | — | May 29, 2020 | An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled. |
| CVE-2020-13487 | Medium (4.8) | 1.6% | — | May 26, 2020 | The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An… |
| CVE-2011-1150 | Medium (6.1) | 0.88% | — | Feb 5, 2020 | bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter. |
| CVE-2011-3710 | Medium (5) | 1.6% | — | Sep 23, 2011 | bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by bb-templates/kakumei/view.php and… |
| CVE-2007-3243 | Medium (4.3) | 1.8% | — | Jun 15, 2007 | Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a… |
| CVE-2007-3244 | High (7.5) | 1.8% | — | Jun 15, 2007 | SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated… |