Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-26173

    JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.

    Last Modified: Nov 21, 2024
    Published: Jun 16, 2022

    CVE-2021-40509

    ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.

    Last Modified: Nov 21, 2024
    Published: Sep 04, 2021

    CVE-2019-7550

    In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product is discontinued.

    Last Modified: Nov 21, 2024
    Published: Feb 12, 2019

    CVE-2013-7209

    Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authentication of administrators for requests that change the user group permissions of arbitrary users via a groupsSave action.

    Last Modified: Apr 11, 2025
    Published: Dec 30, 2013

    CVE-2012-5338

    Open redirect vulnerability in JForum 2.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnPath parameter in a validateLogin action to jforum.page.

    Last Modified: Apr 11, 2025
    Published: Sep 23, 2013
    Items Per Page
    Jforum Vulnerabilities & Security CVEs | CVE-DB