Extension WordPress
Vulnérabilités BuddyBoss Platform
Cette page rassemble les failles publiées pour BuddyBoss Platform, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de BuddyBoss Platform
10 fiches
BuddyBoss Platform <= 3.0.5 – Unauthenticated SQL Injection
The BuddyBoss Platform plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-3.0.5
3.1.0
09/07/2026
BuddyBoss Platform <= 3.0.4 – Authenticated (Subscriber+) PHP Object Injection
The BuddyBoss Platform plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.4 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject…
*-3.0.4
3.0.5
23/06/2026
BuddyBoss Platform and BuddyBoss Theme <= Multiple Versions – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'invitee_name'
The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping.…
*-2.8.50
2.8.51
01/05/2025
BuddyBoss Platform <= 2.8.50 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bp_nouveau_ajax_media_save' function
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.8.50
2.8.51
01/05/2025
BuddyBoss Platform <= 2.8.50 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bbp_topic_title'
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.8.50
2.8.51
01/05/2025
BuddyBoss Platform <= 2.7.70 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link_title'
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.7.70
2.8.00
26/02/2025
BuddyBoss Platform < 2.7.60 – Insecure Direct Object Reference to Private Post Comment Exposure
The BuddyBoss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.7.60 (exclusive) due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level…
[*, 2.7.60)
2.7.60
14/01/2025
Buddyboss Platform <= 2.5.91 – Insecure Direct Object Reference to Authenticated (Subscriber+) Comment on Private Post
The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.91 via the new_activity_comment AJAX action due to missing validation on a user controlled key. This makes it…
*-2.5.91
2.6.0
15/05/2024
Buddyboss Platform <= 2.5.91 – Insecure Direct Object Reference to Authenticated (Subscriber+) Link on Private Post
The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.91 via the activity_mark_fav AJAX action due to missing validation on a user controlled key. This makes it…
*-2.5.91
2.6.0
14/05/2024
Buddyboss Platform <= 1.7.8 – SQL Injection
The Buddyboss Platform plugin for WordPress is vulnerable to SQL Injection via the BP_Notifications_Notification::get_order_by_sql() and BP_Invitation::get_order_by_sql() functions in versions up to, and including, 1.7.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on…
*-1.7.8
1.7.9
16/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.