Buddyboss develops a community and social-networking platform suite that integrates with WordPress ecosystems, where its vulnerability footprint centers on a focused set of products including the Buddyboss Platform and related plugins. The recurring weakness classes—cross-site scripting, authorization bypass, authentication bypass, and sensitive information exposure—reflect the authentication and access-control demands of user-facing community software, with a moderate tendency toward serious severity outcomes. Live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Buddyboss over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56032CRITICAL Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. | Jun 26, 2026 | 9.8 | 36 | NO | NO |
CVE-2025-1909CRITICAL The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the use | May 5, 2025 | 9.8 | 31 | NO | NO |
CVE-2021-44692MEDIUM BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new user, it generates a Unique ID for their profile. This UID is | Jan 26, 2022 | 5.3 | 21 | NO | NO |
CVE-2021-43334MEDIUM BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field. | Jan 26, 2022 | 5.4 | 20 | NO | NO |
CVE-2018-21014MEDIUM The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS. | Sep 9, 2019 | 5.4 | 20 | NO | NO |
CVE-2024-13860MEDIUM The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to ins | May 2, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-13859MEDIUM The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 | May 2, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-13858MEDIUM The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, | May 2, 2025 | 5.4 | 18 | NO | NO |
CVE-2023-45755MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BuddyBoss BuddyPress Global Search plugin <= 1.2.1 versions. | Oct 25, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-32671MEDIUM A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST requ | Oct 3, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Buddyboss.
Media articles that mention a CVE ID that affects a product developed by Buddyboss — matched by CVE ID, not by vendor name.