Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Simple Machines

First CVE: Mar 15, 2004Active for: 22 yearsTotal CVEs: 64
33.8
VTI Score
Medium

Simple Machines operates a popular open-source forum platform that enjoys widespread deployment across community and discussion-based websites, creating a broadly distributed attack surface despite a narrow product portfolio. The vendor's vulnerability profile centers on web application input-handling issues—cross-site scripting, SQL injection, and path traversal—that are characteristic of server-side forum software and recur across both the core Simple Machines Forum product and downstream integrations. While the severity profile of this vendor's vulnerabilities tends to remain modest, the disclosures frequently acquire public exploit code, making timely patching important for administrators of internet-facing instances. Defenders should treat Simple Machines forum instances as requiring regular security updates and monitor the vendor's release cycles closely given the accessibility and appeal of forum platforms to attackers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
64
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Simple Machines over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2004
22 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (64 CVEs).

64 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-4891CRITICAL
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
Jan 15, 20209.842NOYES
CVE-2022-26982HIGH
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by
Apr 5, 20227.238NOYES
CVE-2009-5068HIGH
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins"
Jan 15, 20207.233NOYES
CVE-2026-39903HIGH
Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a si
Jul 10, 20267.132NONO
CVE-2019-11574CRITICAL
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in
Mar 20, 20209.831NONO
CVE-2008-6971HIGH
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator
Aug 13, 20097.531NOYES
CVE-2026-61520HIGH
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated
Jul 14, 20267.730NONO
CVE-2011-1127HIGH
SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers to have an unspecified impact v
Jun 21, 201110.030NONO
CVE-2013-7466HIGH
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.
Mar 7, 20198.829NONO
CVE-2016-5726CRITICAL
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
Feb 9, 20179.829NONO
View all 64 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products64 CVEs
53%
39%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (31.3%)
Unknown44 (68.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (29.7%)
High1 (1.6%)
Unknown44 (68.8%)
User Interaction
None13 (20.3%)
Unknown44 (68.8%)
Required7 (10.9%)
Privileges Required
Low6 (9.4%)
High3 (4.7%)
None11 (17.2%)
Unknown44 (68.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (64 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
26.6% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Machines.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Simple Machines — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Simple Machines's Products

View all 4 CNAs →

Top CWEs