Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SMF — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in SMF, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on Security Module Framework (SMF) and tracks security weaknesses categorized by Common Vulnerabilities and Exposures (CWE). It collects verified vulnerability records associated with SMF, covering the full historical range from initial release through the most recent advisory updates. Readers can use this interface to monitor vendor-issued advisories, analyze specific weakness classes to understand recurring flaw patterns, and review the complete vulnerability history of the SMF product line. The data is structured to facilitate technical analysis and risk assessment for organizations relying on SMF. Entries include details on impact scope and recommended mitigations, supporting security teams in planning patch cycles and evaluating exposure levels. This page serves as a centralized reference for auditing software integrity and tracking how specific security flaws have been identified and resolved within the SMF ecosystem.

Vendor: SMF

CVE ID Title CVSS Severity Published
CVE-2026-43621 Simple Machines Forum < 2.1.7 Authorization Confusion via Profile::load() CWE-863 8.1 High 2026-08-26
CVE-2026-61520 Simple Machines Forum SSRF via image proxy CWE-918 7.7 High 2026-07-14
CVE-2026-39903 Simple Machines Forum Authorization Bypass via AttachmentApprove.php CWE-863 7.1 High 2026-07-10
CVE-2026-26025 free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE  CWE-476 7.5 - 2026-02-24
CVE-2026-26024 free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE  CWE-476 7.5 - 2026-02-24
CVE-2026-25501 free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.DLDR is set but DownlinkDataReport IE is missing CWE-476 7.5 - 2026-02-24
CVE-2026-1684 Free5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of service CWE-404 5.3 Medium 2026-01-30
CVE-2026-1683 Free5GC SMF PFCP handler.go HandlePfcpSessionReportRequest denial of service CWE-404 5.3 Medium 2026-01-30
CVE-2026-1682 Free5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereference CWE-476 5.3 Medium 2026-01-30
CVE-2025-2583 SimpleMachines SMF ManageNews.php cross site scripting CWE-79 3.5 Low 2025-03-21
CVE-2025-2582 SimpleMachines SMF ManageAttachments.php cross site scripting CWE-79 3.5 Low 2025-03-21
CVE-2024-7438 SimpleMachines SMF User Alert Read Status index.php resource injection CWE-99 4.3 Medium 2024-08-03
CVE-2024-7437 SimpleMachines SMF Delete User index.php resource injection CWE-99 5.4 Medium 2024-08-03
CVE-2013-4395 Simple Machines Forum 跨站脚本漏洞 6.1 - 2020-02-12
CVE-2013-0192 Simple Machines Forum 信息泄露漏洞 4.9 - 2020-02-07
CVE-2009-5068 Simple Machines Forum 安全漏洞 7.2 - 2020-01-15

All 16 known CVE vulnerabilities affecting SMF with full Chinese analysis, references, and POCs where available.