Vulnerabilities > Buddyboss > Buddyboss Platform > 1.4.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-05-02 | CVE-2024-13858 | Cross-site Scripting vulnerability in Buddyboss Platform The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. | 5.4 |
2025-05-02 | CVE-2024-13859 | Cross-site Scripting vulnerability in Buddyboss Platform The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. | 5.4 |
2025-05-02 | CVE-2024-13860 | Cross-site Scripting vulnerability in Buddyboss Platform The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. | 5.4 |
2024-06-05 | CVE-2024-4886 | Authorization Bypass Through User-Controlled Key vulnerability in Buddyboss Platform The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request | 4.3 |