Jforum is a discussion-board and community-forum software product that has a narrow but established presence in web-based collaboration deployments. The vendor's vulnerability profile concentrates on web-application input-handling and session-management weaknesses, particularly cross-site request forgery, cross-site scripting, and improper input validation, alongside information-disclosure flaws through error messages—patterns typical of web frameworks with evolving security maturity. Public exploit code has been available for vulnerabilities in this product. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jforum over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7209MEDIUM Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authentication of administrators for reque | Dec 30, 2013 | 6.8 | 34 | NO | YES |
CVE-2022-26173HIGH JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin ac | Jun 16, 2022 | 8.8 | 29 | NO | NO |
CVE-2012-5337MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in jforum.page in JForum 2.1.9 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) match_type, | Feb 24, 2013 | 4.3 | 26 | NO | YES |
CVE-2021-40509MEDIUM ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature. | Sep 4, 2021 | 5.4 | 20 | NO | NO |
CVE-2012-5338MEDIUM Open redirect vulnerability in JForum 2.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnPath parameter in a | Sep 23, 2013 | 5.8 | 19 | NO | NO |
CVE-2019-7550MEDIUM In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresp | Feb 12, 2019 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jforum.
Media articles that mention a CVE ID that affects a product developed by Jforum — matched by CVE ID, not by vendor name.