← Back

Mm Forum

mm_forum

Vendor: Mm Forum Project • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mm Forum Project
1Mm Forum
Nov 21, 2024
Jul 7, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.
1Mm Forum Project
1Mm Forum
May 6, 2026
Oct 3, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to hijack the authentication of users for requests that create posts via unspecified vectors.
1Mm Forum Project
1Mm Forum
May 6, 2026
Oct 3, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecifie...Show more
Unrestricted file upload vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.Show less
1Mm Forum Project
1Mm Forum
May 6, 2026
Oct 3, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.