Skip to main content

Vendor/product archive

simplemachines / simple_machine_forum CVEs

Beta · best-effort

2 CVEs tagged to simplemachines / simple_machine_forum2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2019-11574

Published Mar 20, 2020

An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4891

Published Jan 15, 2020

Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1