Vulnerabilities
Summary — last 7 days
New vulnerabilities3,069▲ 549 vs. last week
Critical / high1,455▲ 270 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)383▲ 176 vs. last week
30 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.31% | — | BbpressAI | 9/11/2026 | 9/11/2026 | Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. | |
| Deferred | Medium (5.3) | 0.31% | — | BbpressAI | 8/31/2026 | 9/2/2026 | Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14. | |
| Deferred | Medium (6.6) | 0.69% | — | Weavertheme Turnkey BbpressAI | 8/16/2026 | 8/20/2026 | The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached through the wvrbbp_save_restore() settings-restore handler). The function reads the… | |
| Deferred | High (7.1) | 0.27% | — | Jezza101 Bbpress Simple Advert UnitsAI | 2/20/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jezza101 bbpress Simple Advert Units bbpress-simple-advert-units allows Reflected XSS.This issue affects bbpress Simple Advert Units: from n/a through <= 0.41. | |
| Deferred | Medium (5.3) | 0.33% | — | Rtcamp Rtmedia FOR Wordpress Buddypress AND BbpressAI | 2/19/2026 | 6/17/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through <= 4.7.8. | |
| Deferred | High (7.1) | 0.25% | — | Usestrict Bbpress NotifyAI | 10/22/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in useStrict bbPress Notify bbpress-notify-nospam allows Reflected XSS.This issue affects bbPress Notify: from n/a through <= 2.19.5. | |
| Deferred | High (7.1) | 0.25% | — | Pascal Casier Bbpress Move TopicsAI | 10/22/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Casier bbPress Move Topics bbp-move-topics allows Reflected XSS.This issue affects bbPress Move Topics: from n/a through <= 1.1.6. | |
| Deferred | Medium (6.5) | 0.20% | — | Milan Petrovic GD GD Bbpress ToolsAI | 9/22/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD bbPress Tools gd-bbpress-tools allows DOM-Based XSS.This issue affects GD bbPress Tools: from n/a through <= 3.5.3. | |
| Deferred | Medium (5.3) | 0.34% | — | Pascal Casier Bbpress APIAI | 6/6/2025 | 6/17/2026 | Missing Authorization vulnerability in Pascal Casier bbPress API bbp-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects bbPress API: from n/a through <= 1.0.14. | |
| Deferred | High (7.1) | 0.29% | — | Antonchanning Bbpress2 Shortcode WhitelistAI | 4/17/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antonchanning bbPress2 shortcode whitelist bbpress2-shortcode-whitelist allows Stored XSS.This issue affects bbPress2 shortcode whitelist: from n/a through <= 2.2.1. | |
| Deferred | High (8.8) | 0.89% | — | Wpzone Inline Image Upload FOR BbpressAI | 3/29/2025 | 6/17/2026 | The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the file uploading functionality in all versions up to, and including, 1.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Deferred | Medium (6.3) | 0.20% | — | BbpressAI | 3/5/2025 | 6/17/2026 | The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11. This is due to missing or incorrect nonce validation on the bbp_user_add_role_on_register() function. This makes it possible for unauthenticated attackers to elevate their privileges to that of a… | |
| Deferred | Medium (6.1) | 0.36% | — | Weavertheme Turnkey BbpressAI | 1/4/2025 | 6/17/2026 | The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Deferred | Medium (6.1) | 0.39% | — | Dev4press GD Bbpress AttachmentsAI | 11/20/2024 | 6/17/2026 | The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Modified | Medium (6.1) | 0.29% | — | Usestrict Bbpress Notify | 7/21/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vinny Alves (UseStrict Consulting) bbPress Notify allows Reflected XSS.This issue affects bbPress Notify: from n/a through 2.18.3. | |
| Modified | High (8.8) | 0.23% | — | Wpzone Inline Image Upload FOR Bbpress | 1/5/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Inline Image Upload for BBPress.This issue affects Inline Image Upload for BBPress: from n/a through 1.1.18. | |
| Modified | High (8.8) | 0.31% | — | Casier Bbpress Toolkit | 11/9/2023 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier bbPress Toolkit plugin <= 1.0.12 versions. | |
| Modified | Medium (6.1) | 0.46% | — | Casier Bbpress Toolkit | 8/30/2023 | 6/17/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pascal Casier bbPress Toolkit plugin <= 1.0.12 versions. | |
| Modified | Medium (4.8) | 0.39% | — | Wpforthewin Bbpress Voting | 4/6/2023 | 6/17/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP For The Win bbPress Voting plugin <= 2.1.11.0 versions. | |
| Modified | Medium (5.4) | 0.43% | — | Dev4press GD Bbpress Attachments | 12/6/2022 | 6/17/2026 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in GD bbPress Attachments plugin <= 4.3.1 on WordPress. | |
| Modified | Critical (9.8) | 44% | — | Bbpress | 5/29/2020 | 6/17/2026 | An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled. | |
| Modified | Medium (4.8) | 1.6% | — | Bbpress | 5/26/2020 | 6/17/2026 | The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI. | |
| Modified | Medium (6.1) | 0.88% | — | Bbpress | 2/5/2020 | 6/16/2026 | bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter. | |
| Modified | High (8.8) | 0.67% | — | Bbpress Move Topics Project Bbpress Move Topics | 8/27/2019 | 6/17/2026 | The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF. | |
| Modified | Critical (9.8) | 2.1% | — | Bbpress Move Topics Project Bbpress Move Topics | 8/27/2019 | 6/17/2026 | The bbp-move-topics plugin before 1.1.6 for WordPress has code injection. |