Buddyboss
Buddyboss Platform: vulnerabilidades y CVE
Buddyboss Platform tiene 9 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses2
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59514 | Crítica (9.3) | 0.40% | — | 23 jul 2026 | Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. |
| CVE-2026-56032 | Crítica (9.8) | 0.56% | — | 26 jun 2026 | Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. |
| CVE-2024-12767 | Baja (3.5) | 0.33% | — | 15 may 2025 | The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts |
| CVE-2025-1909 | Crítica (9.8) | 0.64% | — | 5 may 2025 | The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth… |
| CVE-2024-13860 | Media (5.4) | 0.28% | — | 2 may 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output… |
| CVE-2024-13859 | Media (5.4) | 0.28% | — | 2 may 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization… |
| CVE-2024-13858 | Media (5.4) | 0.30% | — | 2 may 2025 | The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to… |
| CVE-2024-13402 | Media (5.4) | 0.24% | — | 27 feb 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output… |
| CVE-2024-4886 | Media (4.3) | 0.38% | — | 5 jun 2024 | The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.