Simple Machines operates a popular open-source forum platform that enjoys widespread deployment across community and discussion-based websites, creating a broadly distributed attack surface despite a narrow product portfolio. The vendor's vulnerability profile centers on web application input-handling issues—cross-site scripting, SQL injection, and path traversal—that are characteristic of server-side forum software and recur across both the core Simple Machines Forum product and downstream integrations. While the severity profile of this vendor's vulnerabilities tends to remain modest, the disclosures frequently acquire public exploit code, making timely patching important for administrators of internet-facing instances. Defenders should treat Simple Machines forum instances as requiring regular security updates and monitor the vendor's release cycles closely given the accessibility and appeal of forum platforms to attackers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simple Machines over time
Signals from CVEs in this vendor scope (64 CVEs).
64 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4891CRITICAL Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements. | Jan 15, 2020 | 9.8 | 42 | NO | YES |
CVE-2022-26982HIGH SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by | Apr 5, 2022 | 7.2 | 38 | NO | YES |
CVE-2009-5068HIGH There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" | Jan 15, 2020 | 7.2 | 33 | NO | YES |
CVE-2026-39903HIGH Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a si | Jul 10, 2026 | 7.1 | 32 | NO | NO |
CVE-2019-11574CRITICAL An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in | Mar 20, 2020 | 9.8 | 31 | NO | NO |
CVE-2008-6971HIGH The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator | Aug 13, 2009 | 7.5 | 31 | NO | YES |
CVE-2026-61520HIGH Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated | Jul 14, 2026 | 7.7 | 30 | NO | NO |
CVE-2011-1127HIGH SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers to have an unspecified impact v | Jun 21, 2011 | 10.0 | 30 | NO | NO |
CVE-2013-7466HIGH Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install. | Mar 7, 2019 | 8.8 | 29 | NO | NO |
CVE-2016-5726CRITICAL Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter. | Feb 9, 2017 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (64 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Machines.
Media articles that mention a CVE ID that affects a product developed by Simple Machines — matched by CVE ID, not by vendor name.