VYPR

Buddyboss Platform

by Buddyboss

Source repositories

CVEs (4)

  • CVE-2024-13860MedMay 2, 2025
    risk 0.42cvss 6.4epss 0.00

    The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2024-13859MedMay 2, 2025
    risk 0.42cvss 6.4epss 0.00

    The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-13858MedMay 2, 2025
    risk 0.42cvss 6.4epss 0.00

    The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping.…

  • CVE-2024-4886MedJun 5, 2024
    risk 0.28cvss 4.3epss 0.00

    The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request