Extension WordPress

Vulnérabilités BuddyBoss Platform

Cette page rassemble les failles publiées pour BuddyBoss Platform, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
0Critiques
10Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de BuddyBoss Platform

10 fiches

CVE-2024-13858 Moyenne · 6,4
BuddyBoss Platform

BuddyBoss Platform and BuddyBoss Theme <= Multiple Versions – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'invitee_name'

The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping.…

Versions affectées

*-2.8.50

Correctif

2.8.51

Publication

01/05/2025

CVE-2024-13859 Moyenne · 6,4
BuddyBoss Platform

BuddyBoss Platform <= 2.8.50 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bp_nouveau_ajax_media_save' function

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-2.8.50

Correctif

2.8.51

Publication

01/05/2025

CVE-2024-13860 Moyenne · 6,4
BuddyBoss Platform

BuddyBoss Platform <= 2.8.50 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bbp_topic_title'

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-2.8.50

Correctif

2.8.51

Publication

01/05/2025

CVE-2024-13402 Moyenne · 6,4
BuddyBoss Platform

BuddyBoss Platform <= 2.7.70 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link_title'

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-2.7.70

Correctif

2.8.00

Publication

26/02/2025

CVE-2024-12767 Moyenne · 4,3
BuddyBoss Platform

BuddyBoss Platform < 2.7.60 – Insecure Direct Object Reference to Private Post Comment Exposure

The BuddyBoss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.7.60 (exclusive) due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level…

Versions affectées

[*, 2.7.60)

Correctif

2.7.60

Publication

14/01/2025

CVE-2024-4886 Moyenne · 4,3
BuddyBoss Platform

Buddyboss Platform <= 2.5.91 – Insecure Direct Object Reference to Authenticated (Subscriber+) Comment on Private Post

The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.91 via the new_activity_comment AJAX action due to missing validation on a user controlled key. This makes it…

Versions affectées

*-2.5.91

Correctif

2.6.0

Publication

15/05/2024

CVE-2024-4750 Moyenne · 4,3
BuddyBoss Platform

Buddyboss Platform <= 2.5.91 – Insecure Direct Object Reference to Authenticated (Subscriber+) Link on Private Post

The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.91 via the activity_mark_fav AJAX action due to missing validation on a user controlled key. This makes it…

Versions affectées

*-2.5.91

Correctif

2.6.0

Publication

14/05/2024

Vulnérabilité Élevée · 7,2
BuddyBoss Platform

Buddyboss Platform <= 1.7.8 – SQL Injection

The Buddyboss Platform plugin for WordPress is vulnerable to SQL Injection via the BP_Notifications_Notification::get_order_by_sql() and BP_Invitation::get_order_by_sql() functions in versions up to, and including, 1.7.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on…

Versions affectées

*-1.7.8

Correctif

1.7.9

Publication

16/09/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités