Beehive Forum is a niche open-source community discussion platform whose vulnerability footprint centers on a single product and recurs through application-layer input-handling issues including cross-site scripting and SQL injection. Vulnerabilities affecting this vendor frequently acquire public exploit code, making patching and input-validation hardening particularly important for deployments exposed to untrusted networks. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beehive Forum over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-50910CRITICAL Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can i | Jan 13, 2026 | 9.8 | 34 | NO | NO |
CVE-2012-0900MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php | Jan 20, 2012 | 4.3 | 26 | NO | YES |
CVE-2005-4460MEDIUM Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (3 | Dec 21, 2005 | 5.1 | 23 | NO | YES |
CVE-2015-2198MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage_url, | Mar 3, 2015 | 4.3 | 21 | NO | YES |
CVE-2007-3212MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, | Jun 14, 2007 | 4.3 | 21 | NO | YES |
CVE-2007-6014HIGH SQL injection vulnerability in post.php in Beehive Forum 0.7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t_dedupe parameter. | Dec 5, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-6241HIGH Multiple unspecified vulnerabilities in Beehive Forum 0.7.1 have unknown "critical" impact and attack vectors, different issues than CVE-2007-6014. | Dec 5, 2007 | 7.5 | 19 | NO | NO |
CVE-2005-2421HIGH Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter. | Aug 3, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-2422MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter. | Aug 3, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beehive Forum.
Media articles that mention a CVE ID that affects a product developed by Beehive Forum — matched by CVE ID, not by vendor name.