| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-4406 | wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar | tomdever | wpForo Forum | Medium | 5.4 | 2025-07-10 01:43:43 | Deep Dive |
| CVE-2025-4224 | wpForo + wpForo Advanced Attachments <= 3.1.3 - Unauthenticated Stored Cross-Site Scripting | gVectors | wpForo + wpForo Advanced Attachments | High | 7.2 | 2025-06-03 02:27:35 | Deep Dive |
| CVE-2025-31420 | WordPress wpForo Forum plugin <= 2.4.2 - Privilege Escalation vulnerability | Tomdever | wpForo Forum | - | - | 2025-04-04 13:00:14 | Deep Dive |
| CVE-2025-0764 | wpForo Forum <= 2.4.1 - Authenticated (Subscriber+) Arbitrary File Read in update | tomdever | wpForo Forum | Medium | 6.5 | 2025-02-28 07:03:46 | Deep Dive |
| CVE-2023-47869 | WordPress wpForo plugin <= 2.2.5 - Broken Access Control + CSRF vulnerability | Tomdever | wpForo Forum | Medium | 4.3 | 2024-12-09 11:30:34 | Deep Dive |
| CVE-2024-43289 | WordPress wpForo Forum plugin <= 2.3.4 - Unauthenticated Sensitive Data Exposure vulnerability | gVectors Team | wpForo Forum | High | 7.5 | 2024-08-26 16:06:02 | Deep Dive |
| CVE-2024-43288 | WordPress wpForo Forum plugin <= 2.3.4 - Insecure Direct Object References (IDOR) vulnerability | gVectors Team | wpForo Forum | Medium | 4.3 | 2024-08-18 21:33:37 | Deep Dive |
| CVE-2022-38055 | WordPress wpForo Forum plugin <= 2.0.9 - Auth. HTML Injection vulnerability | gVectors Team | wpForo Forum | Medium | 4.3 | 2024-06-21 15:52:08 | Deep Dive |
| CVE-2024-3200 | wpForo Forum <= 2.3.3 - Authenticated (Contributor+) SQL Injection | tomdever | wpForo Forum | Critical | 9.9 | 2024-06-01 08:38:58 | Deep Dive |
| CVE-2023-47868 | WordPress wpForo plugin <= 2.2.3 - Privilege Escalation vulnerability | wpForo | wpForo Forum | High | 7.3 | 2024-05-17 08:37:33 | Deep Dive |
| CVE-2023-47870 | WordPress wpForo Forum Plugin <= 2.2.6 is vulnerable to Broken Access Control and Cross Site Request Forgery (CSRF) | gVectors Team | wpForo Forum | High | 7.1 | 2023-11-30 17:26:37 | Deep Dive |
| CVE-2023-47872 | WordPress wpForo Forum Plugin <= 2.2.3 is vulnerable to Cross Site Scripting (XSS) | gVectors Team | wpForo Forum | Medium | 6.5 | 2023-11-30 16:46:53 | Deep Dive |
| CVE-2023-2309 | wpForo Forum < 2.1.9 - Reflected Cross-Site Scripting | Unknown | wpForo Forum | 中危 | - | 2023-07-24 10:20:24 | Deep Dive |
| CVE-2023-2249 | wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents | tomdever | wpForo Forum | High | 8.8 | 2023-06-09 05:33:22 | Deep Dive |
| CVE-2022-40192 | WordPress wpForo Forum plugin <= 2.0.9 - Cross-Site Request Forgery (CSRF) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | High | 7.1 | 2022-11-17 22:14:27 | Deep Dive |
| CVE-2022-40200 | WordPress wpForo Forum plugin <= 2.0.9 - Auth. Arbitrary File Upload vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | Critical | 9.9 | 2022-11-17 22:01:00 | Deep Dive |
| CVE-2022-40206 | WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | Medium | 6.3 | 2022-11-08 18:31:21 | Deep Dive |
| CVE-2022-40205 | WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | Medium | 5.4 | 2022-11-08 18:26:59 | Deep Dive |
| CVE-2022-40632 | WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | Medium | 5.4 | 2022-11-08 18:23:19 | Deep Dive |
| CVE-2022-38144 | WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerability | gVectors Team | wpForo Forum (WordPress plugin) | 高危 | - | 2022-09-09 14:39:54 | Deep Dive |