Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gvectors wpforo vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2018-11515
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
Gvectors Wpforo
6.1
CVSSv3
CVE-2021-24406
The wpForo Forum WordPress plugin prior to 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an malicious user to induce a user to use a login URL redirecting to a we...
Gvectors Wpforo Forum
5.4
CVSSv3
CVE-2022-40632
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
Gvectors Wpforo Forum
8.8
CVSSv3
CVE-2023-47870
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a up...
Gvectors Wpforo Forum
5.4
CVSSv3
CVE-2023-47872
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.This issue affects wpForo Forum: from n/a up to and including 2.2.3.
Gvectors Wpforo Forum
8.8
CVSSv3
CVE-2022-40192
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Gvectors Wpforo Forum
8.8
CVSSv3
CVE-2022-40200
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Gvectors Wpforo Forum
9.8
CVSSv3
CVE-2018-16613
An issue exists in the update function in the wpForo Forum plugin prior to 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.
Gvectors Wpforo Forum
8.8
CVSSv3
CVE-2019-19109
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
Gvectors Wpforo 1.6.5
4.8
CVSSv3
CVE-2019-19110
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
Gvectors Wpforo 1.6.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27802
template injection
CVE-2024-0044
code injection
CVE-2024-35474
CVE-2024-27857
CVE-2024-23251
CVE-2024-23692
physical
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »