Beehiveforum is a modestly represented forum software platform whose vulnerability footprint centers on a single primary product. The durable signal is centered on authentication and account-recovery mechanisms, with observed weaknesses in password reset functionality that could enable unauthorized account access. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beehiveforum over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-50910CRITICAL Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can i | Jan 13, 2026 | 9.8 | 34 | NO | NO |
CVE-2005-4461HIGH SQL injection vulnerability in index.php in Beehive Forum 0.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_sess parameter. | Dec 21, 2005 | 7.5 | 28 | NO | YES |
CVE-2012-0900MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php | Jan 20, 2012 | 4.3 | 26 | NO | YES |
CVE-2005-4460MEDIUM Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (3 | Dec 21, 2005 | 5.1 | 23 | NO | YES |
CVE-2015-2198MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage_url, | Mar 3, 2015 | 4.3 | 21 | NO | YES |
CVE-2007-3212MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, | Jun 14, 2007 | 4.3 | 21 | NO | YES |
CVE-2007-6014HIGH SQL injection vulnerability in post.php in Beehive Forum 0.7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t_dedupe parameter. | Dec 5, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-6241HIGH Multiple unspecified vulnerabilities in Beehive Forum 0.7.1 have unknown "critical" impact and attack vectors, different issues than CVE-2007-6014. | Dec 5, 2007 | 7.5 | 19 | NO | NO |
CVE-2005-2421HIGH Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter. | Aug 3, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-2423MEDIUM Beehive Forum allows remote attackers to obtain sensitive information via (1) an invalid final_uri or sort_by parameter to index.php or a direct request to (2) admin.php, (3) attac | Aug 3, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beehiveforum.
Media articles that mention a CVE ID that affects a product developed by Beehiveforum — matched by CVE ID, not by vendor name.