Vulnerabilities > Buddyboss
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-05-05 | CVE-2025-1909 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Buddyboss Platform The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. | 9.8 |
2025-05-02 | CVE-2024-13858 | Cross-site Scripting vulnerability in Buddyboss Platform The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping. | 5.4 |
2025-05-02 | CVE-2024-13859 | Cross-site Scripting vulnerability in Buddyboss Platform The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. | 5.4 |
2025-05-02 | CVE-2024-13860 | Cross-site Scripting vulnerability in Buddyboss Platform The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-27 | CVE-2024-13402 | Cross-site Scripting vulnerability in Buddyboss Platform The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. | 5.4 |
2024-06-05 | CVE-2024-4886 | Authorization Bypass Through User-Controlled Key vulnerability in Buddyboss Platform The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request | 4.3 |
2023-10-25 | CVE-2023-45755 | Unspecified vulnerability in Buddyboss Buddypress Global Search 1.2.1 Auth. | 4.8 |
2023-10-03 | CVE-2023-32669 | Authorization Bypass Through User-Controlled Key vulnerability in Buddyboss 2.2.9 Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. | 5.4 |
2023-10-03 | CVE-2023-32670 | Cross-site Scripting vulnerability in Buddyboss 2.2.9 Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded. | 5.4 |
2023-10-03 | CVE-2023-32671 | Cross-site Scripting vulnerability in Buddyboss 2.2.9 A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. | 5.4 |