← Back

Bbpress

bbpress

Vendor: Bbpress • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bbpress
1Bbpress
Jun 17, 2026
May 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
1Bbpress
1Bbpress
Jun 17, 2026
May 26, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administr...Show more
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.Show less
1Bbpress
1Bbpress
Nov 21, 2024
Feb 5, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.
1Bbpress
1Bbpress
Apr 29, 2026
Sep 23, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by bb-templates/kakumei/view.php and cer...Show more
bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by bb-templates/kakumei/view.php and certain other files.Show less
1Bbpress
1Bbpress
Apr 23, 2026
Jun 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by...Show more
SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug."Show less
1Bbpress
1Bbpress
Apr 23, 2026
Jun 15, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a...Show more
Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header.Show less