Extension WordPress
Vulnérabilités WP Forum Server
Cette page rassemble les failles publiées pour WP Forum Server, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Forum Server
6 fiches
WP Forum Server <= 1.8.2 – Cross-Site Request Forgery
The WP Forum Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for…
*-1.8.2
Non indiqué
27/06/2025
WP Forum Server <= 1.8.2 – Authenticated (Administrator+) SQL Injection
The WP Forum Server plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-1.8.2
Non indiqué
27/06/2025
WP Forum Server < 1.7.4 – SQL Injection
SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action.
[*, 1.7.4)
1.7.4
15/05/2012
WP Forum Server < 1.7.5 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1.7.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the groupid parameter in an addforum action to wp-admin/admin.php.
[*, 1.7.5)
1.7.5
15/05/2012
WP Forum Server <= 1.7.3 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP Forum Server plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the (1) groupid parameter in an editgroup action or (2) usergroup_id parameter in an edit_usergroup action in versions up to, and including, 1.7.3 due…
*-1.7.3
1.7.4
15/05/2012
WP Forum Server <= 1.6.5 – SQL Injection
Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not…
*-1.6.5
1.6.6
22/02/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.