Forem is an open-source community platform and publishing engine used to power discussion forums and developer communities, with its vulnerability footprint concentrated in the platform product itself. The observed weakness pattern centers on server-side request forgery, reflecting exposure inherent to a web application that processes user-controlled requests and fetches external resources. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Forem over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27160HIGH forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows attackers to access network resou | Mar 31, 2023 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Forem.
Media articles that mention a CVE ID that affects a product developed by Forem — matched by CVE ID, not by vendor name.