« Volver al listado

Buddyboss

Buddyboss Platform: vulnerabilidades y CVE

Buddyboss Platform tiene 9 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses2
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-59514Crítica (9.3)0.40%—23 jul 2026
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
CVE-2026-56032Crítica (9.8)0.56%—26 jun 2026
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
CVE-2024-12767Baja (3.5)0.33%—15 may 2025
The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts
CVE-2025-1909Crítica (9.8)0.64%—5 may 2025
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth…
CVE-2024-13860Media (5.4)0.28%—2 may 2025
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output…
CVE-2024-13859Media (5.4)0.28%—2 may 2025
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization…
CVE-2024-13858Media (5.4)0.30%—2 may 2025
The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to…
CVE-2024-13402Media (5.4)0.24%—27 feb 2025
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output…
CVE-2024-4886Media (4.3)0.38%—5 jun 2024
The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Buddyboss