Asgaros develops a focused forum-community platform that, despite a narrow product scope, occupies a meaningful niche in the vulnerability landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, clustering around application-layer injection and validation weaknesses—SQL injection, cross-site scripting, code injection, cross-site request forgery, and unsafe deserialization—that are characteristic of web applications handling untrusted user input and session state. Defenders deploying this forum software should prioritize patching and input-sanitization review; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asgaros over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24827CRITICAL The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthentica | Nov 8, 2021 | 9.8 | 48 | NO | YES |
CVE-2022-41608HIGH Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum plugin <= 2.2.0 versions. | May 22, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-0411HIGH The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to | Feb 28, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-11452HIGH The Asgaros Forum plugin for WordPress is vulnerable to SQL Injection via the '$_COOKIE['asgarosforum_unread_exclude']' cookie in all versions up to, and including, 3.1.0 due to in | Nov 8, 2025 | 7.5 | 26 | NO | NO |
CVE-2024-22284CRITICAL Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2. | Jan 24, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-5604CRITICAL The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthentica | Nov 27, 2023 | 9.8 | 26 | NO | NO |
CVE-2021-25045HIGH The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL inje | Jan 24, 2022 | 7.2 | 25 | NO | NO |
CVE-2024-32440HIGH Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.8.0. | Apr 15, 2024 | 8.8 | 23 | NO | NO |
CVE-2021-42365MEDIUM The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the name parameter found in the ~/admin/tables/admin-structure-tab | Nov 29, 2021 | 4.8 | 19 | NO | NO |
CVE-2025-39514MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asgaros Asgaros Forum asgaros-forum allows Stored XSS.This issue affects Asgar | Apr 16, 2025 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asgaros.
Media articles that mention a CVE ID that affects a product developed by Asgaros — matched by CVE ID, not by vendor name.