Fudforum is a web-based forum and community platform whose vulnerability profile concentrates in input-handling and code-injection weaknesses spanning cross-site scripting, OS command injection, code injection, and unrestricted file uploads. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, reflecting the parsing and generation demands of a web application handling user-supplied content and file submissions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fudforum over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18873CRITICAL FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the syst | Nov 12, 2019 | 9.0 | 43 | NO | YES |
CVE-2021-27519MEDIUM A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter. | Mar 19, 2021 | 6.1 | 42 | NO | YES |
CVE-2021-27520MEDIUM A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter. | Mar 19, 2021 | 6.1 | 41 | NO | YES |
CVE-2013-2267HIGH PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. | Jan 27, 2020 | 7.2 | 36 | NO | YES |
CVE-2022-30860HIGH FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel. | Jun 6, 2022 | 7.2 | 33 | NO | NO |
CVE-2019-18839CRITICAL FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system usi | Nov 13, 2019 | 9.0 | 30 | NO | NO |
CVE-2022-28545MEDIUM FUDforum 3.1.1 is vulnerable to Stored XSS. | May 6, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-30861MEDIUM FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature. | Jun 6, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-30951MEDIUM FUDforum v3.1.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the chpos parameter at /adm/admsmiley.php. | Apr 17, 2024 | 6.1 | 18 | NO | NO |
CVE-2022-30863MEDIUM FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Panel. | Jun 6, 2022 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fudforum.
Media articles that mention a CVE ID that affects a product developed by Fudforum — matched by CVE ID, not by vendor name.