Pressforward is a content curation and publishing platform with a narrowly scoped vulnerability profile centered on its core product. The durable signal reflects application-layer input-handling weaknesses, specifically cross-site scripting vulnerabilities in web page generation; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pressforward over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-28987MEDIUM Server-Side Request Forgery (SSRF) vulnerability in PressForward PressForward pressforward allows Server Side Request Forgery.This issue affects PressForward: from n/a through <= 5 | Aug 14, 2025 | 6.4 | 22 | NO | NO |
CVE-2017-12948MEDIUM Core\Admin\PFTemplater.php in the PressForward plugin 4.3.0 and earlier for WordPress has XSS in the PATH_INFO to wp-admin/admin.php, related to PHP_SELF. | Aug 18, 2017 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pressforward.
Media articles that mention a CVE ID that affects a product developed by Pressforward — matched by CVE ID, not by vendor name.