Simple Machines

    Dashboard / Vendors

    Products: 6
    Vulnerabilities: 31
    Known Exploited: 0
    0
    Critical Level Threats
    11
    High Level Threats
    20
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2012-5903

    Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.php.

    Last Modified: Apr 11, 2025
    Published: Nov 17, 2012

    CVE-2008-7035

    Cross-site scripting (XSS) vulnerability in an unspecified component in Simple Machines phpRaider 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the resistance field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Last Modified: Apr 23, 2026
    Published: Aug 24, 2009

    CVE-2009-2385

    SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.

    Last Modified: Apr 23, 2026
    Published: Jul 08, 2009

    CVE-2008-6741

    SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "\" (backslash) sequence that does not quote the "'" (single quote) character, as demonstrated via a manlabels action to index.php.

    Last Modified: Apr 23, 2026
    Published: Apr 21, 2009

    CVE-2008-6657

    Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.

    Last Modified: Apr 23, 2026
    Published: Apr 07, 2009
    Items Per Page
    Simple_Machines Vulnerabilities & Security CVEs | CVE-DB