Vulnerabilities

Summary — last 7 days

New vulnerabilities3,069▲ 549 vs. last week
Critical / high1,455▲ 270 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)383▲ 176 vs. last week
–

30 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)0.31%—BbpressAI9/11/20269/11/2026
Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.
DeferredMedium (5.3)0.31%—BbpressAI8/31/20269/2/2026
Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14.
DeferredMedium (6.6)0.69%—Weavertheme Turnkey BbpressAI8/16/20268/20/2026
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached through the wvrbbp_save_restore() settings-restore handler). The function reads the…
DeferredHigh (7.1)0.27%—Jezza101 Bbpress Simple Advert UnitsAI2/20/20266/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jezza101 bbpress Simple Advert Units bbpress-simple-advert-units allows Reflected XSS.This issue affects bbpress Simple Advert Units: from n/a through <= 0.41.
DeferredMedium (5.3)0.33%—Rtcamp Rtmedia FOR Wordpress Buddypress AND BbpressAI2/19/20266/17/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through <= 4.7.8.
DeferredHigh (7.1)0.25%—Usestrict Bbpress NotifyAI10/22/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in useStrict bbPress Notify bbpress-notify-nospam allows Reflected XSS.This issue affects bbPress Notify: from n/a through <= 2.19.5.
DeferredHigh (7.1)0.25%—Pascal Casier Bbpress Move TopicsAI10/22/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Casier bbPress Move Topics bbp-move-topics allows Reflected XSS.This issue affects bbPress Move Topics: from n/a through <= 1.1.6.
DeferredMedium (6.5)0.20%—Milan Petrovic GD GD Bbpress ToolsAI9/22/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD bbPress Tools gd-bbpress-tools allows DOM-Based XSS.This issue affects GD bbPress Tools: from n/a through <= 3.5.3.
DeferredMedium (5.3)0.34%—Pascal Casier Bbpress APIAI6/6/20256/17/2026
Missing Authorization vulnerability in Pascal Casier bbPress API bbp-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects bbPress API: from n/a through <= 1.0.14.
DeferredHigh (7.1)0.29%—Antonchanning Bbpress2 Shortcode WhitelistAI4/17/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antonchanning bbPress2 shortcode whitelist bbpress2-shortcode-whitelist allows Stored XSS.This issue affects bbPress2 shortcode whitelist: from n/a through <= 2.2.1.
DeferredHigh (8.8)0.89%—Wpzone Inline Image Upload FOR BbpressAI3/29/20256/17/2026
The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the file uploading functionality in all versions up to, and including, 1.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
DeferredMedium (6.3)0.20%—BbpressAI3/5/20256/17/2026
The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11. This is due to missing or incorrect nonce validation on the bbp_user_add_role_on_register() function. This makes it possible for unauthenticated attackers to elevate their privileges to that of a…
DeferredMedium (6.1)0.36%—Weavertheme Turnkey BbpressAI1/4/20256/17/2026
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
DeferredMedium (6.1)0.39%—Dev4press GD Bbpress AttachmentsAI11/20/20246/17/2026
The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute…
ModifiedMedium (6.1)0.29%—Usestrict Bbpress Notify7/21/20246/17/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vinny Alves (UseStrict Consulting) bbPress Notify allows Reflected XSS.This issue affects bbPress Notify: from n/a through 2.18.3.
ModifiedHigh (8.8)0.23%—Wpzone Inline Image Upload FOR Bbpress1/5/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Inline Image Upload for BBPress.This issue affects Inline Image Upload for BBPress: from n/a through 1.1.18.
ModifiedHigh (8.8)0.31%—Casier Bbpress Toolkit11/9/20236/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier bbPress Toolkit plugin <= 1.0.12 versions.
ModifiedMedium (6.1)0.46%—Casier Bbpress Toolkit8/30/20236/17/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pascal Casier bbPress Toolkit plugin <= 1.0.12 versions.
ModifiedMedium (4.8)0.39%—Wpforthewin Bbpress Voting4/6/20236/17/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP For The Win bbPress Voting plugin <= 2.1.11.0 versions.
ModifiedMedium (5.4)0.43%—Dev4press GD Bbpress Attachments12/6/20226/17/2026
Auth. Stored Cross-Site Scripting (XSS) vulnerability in GD bbPress Attachments plugin <= 4.3.1 on WordPress.
ModifiedCritical (9.8)44%—Bbpress5/29/20206/17/2026
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
ModifiedMedium (4.8)1.6%—Bbpress5/26/20206/17/2026
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
ModifiedMedium (6.1)0.88%—Bbpress2/5/20206/16/2026
bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.
ModifiedHigh (8.8)0.67%—Bbpress Move Topics Project Bbpress Move Topics8/27/20196/17/2026
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
ModifiedCritical (9.8)2.1%—Bbpress Move Topics Project Bbpress Move Topics8/27/20196/17/2026
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.