Vulnerabilities > Buddypress > Buddypress > 1.9.2

DATE CVE VULNERABILITY TITLE RISK
2023-12-29 CVE-2023-50880 Cross-site Scripting vulnerability in Buddypress
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The BuddyPress Community BuddyPress allows Stored XSS.This issue affects BuddyPress: from n/a through 11.3.1.
network
low complexity
buddypress CWE-79
5.4
2017-03-17 CVE-2017-6954 Improper Privilege Management vulnerability in Buddypress
An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress.
network
low complexity
buddypress CWE-269
4.0