Boss Media Buddyboss Platform vulnerabilities

4 known vulnerabilities affecting boss_media/buddyboss_platform.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2024-13858MEDIUMCVSS 5.4≤ 2.8.502025-05-02
CVE-2024-13858 [MEDIUM] CWE-79 CVE-2024-13858: The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site S The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level acces
cvelistv5nvd
CVE-2024-13859MEDIUMCVSS 5.4≤ 2.8.502025-05-02
CVE-2024-13859 [MEDIUM] CWE-79 CVE-2024-13859: The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary
cvelistv5nvd
CVE-2024-13860MEDIUMCVSS 5.4≤ 2.8.502025-05-02
CVE-2024-13860 [MEDIUM] CWE-79 CVE-2024-13860: The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bb The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web script
cvelistv5nvd
CVE-2024-13402MEDIUMCVSS 5.4≤ 2.7.702025-02-27
CVE-2024-13402 [MEDIUM] CWE-79 CVE-2024-13402: The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘li The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in
cvelistv5nvd