Vulnerabilities > Buddyboss

DATE CVE VULNERABILITY TITLE RISK
2025-05-05 CVE-2025-1909 Authentication Bypass Using an Alternate Path or Channel vulnerability in Buddyboss Platform
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01.
network
low complexity
buddyboss CWE-288
critical
9.8
2025-05-02 CVE-2024-13858 Cross-site Scripting vulnerability in Buddyboss Platform
The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping.
network
low complexity
buddyboss CWE-79
5.4
2025-05-02 CVE-2024-13859 Cross-site Scripting vulnerability in Buddyboss Platform
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping.
network
low complexity
buddyboss CWE-79
5.4
2025-05-02 CVE-2024-13860 Cross-site Scripting vulnerability in Buddyboss Platform
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping.
network
low complexity
buddyboss CWE-79
5.4
2025-02-27 CVE-2024-13402 Cross-site Scripting vulnerability in Buddyboss Platform
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping.
network
low complexity
buddyboss CWE-79
5.4
2024-06-05 CVE-2024-4886 Authorization Bypass Through User-Controlled Key vulnerability in Buddyboss Platform
The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request
network
low complexity
buddyboss CWE-639
4.3
2023-10-25 CVE-2023-45755 Unspecified vulnerability in Buddyboss Buddypress Global Search 1.2.1
Auth.
network
low complexity
buddyboss
4.8
2023-10-03 CVE-2023-32669 Authorization Bypass Through User-Controlled Key vulnerability in Buddyboss 2.2.9
Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums.
network
low complexity
buddyboss CWE-639
5.4
2023-10-03 CVE-2023-32670 Cross-site Scripting vulnerability in Buddyboss 2.2.9
Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.
network
low complexity
buddyboss CWE-79
5.4
2023-10-03 CVE-2023-32671 Cross-site Scripting vulnerability in Buddyboss 2.2.9
A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9.
network
low complexity
buddyboss CWE-79
5.4