Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
simple machines simple machines forum vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-3309
Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote malicious users to execute arbitrary PHP code during (1) creation or (2) editing of a message.
Simple Machines Simple Machines Forum 1.1.2
NA
CVE-2006-0896
Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote malicious users to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field.
Simple Machines Simple Machines Forum 1.0.6
NA
CVE-2008-6544
Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote malicious users to execute arbitrary PHP code via a URL in the (1) settings[default_theme_dir] parameter to Sources/Subs-Graphics.php and (2) settings[default_theme_dir] parameter...
Simple Machines Simple Machines Forum 1.1.4
1 EDB exploit
NA
CVE-2007-5943
Simple Machines Forum (SMF) 1.1.4 allows remote malicious users to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that message.
Simple Machines Simple Machines Forum 1.1.4
NA
CVE-2005-2817
Simple Machines Forum (SMF) 1-0-5 and previous versions supports the use of URLs for avatar images, which allows remote malicious users to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.
Simple Machines Simple Machines Forum 1.0.5
NA
CVE-2004-1996
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote malicious users to inject arbitrary web script via the size tag.
Simple Machines Smf 1.0 Beta4p
Simple Machines Smf 1.0 Beta5p
Simple Machines Smf 1.0 Beta4.1
1 EDB exploit
7.2
CVSSv3
CVE-2022-26982
SimpleMachinesForum 2.1.1 and previous versions allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to ...
Simplemachines Simple Machines Forum
9.8
CVSSv3
CVE-2018-10305
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) prior to 2.0.15 does not properly use the possible_users variable in a query, which might allow malicious users to bypass intended access restrictions.
Simplemachines Simple Machines Forum
6.1
CVSSv3
CVE-2013-4395
Simple Machines Forum (SMF) up to and including 2.0.5 has XSS
Simplemachines Simple Machines Forum
6.5
CVSSv3
CVE-2019-12490
An issue exists in Simple Machines Forum (SMF) prior to 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.
Simplemachines Simple Machines Forum
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »