Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Simplemachines

First CVE: Mar 15, 2004Active for: 22 yearsTotal CVEs: 64
43.8
VTI Score
High

Simple Machines develops and maintains Simple Machines Forum (SMF), a widely embedded open-source discussion-board platform that powers community sections across many websites, alongside integrations with e-commerce systems such as OpenCart. Despite a narrow product portfolio, the vendor's vulnerability footprint is prominent in the landscape due to SMF's broad deployment and longevity as a self-hosted application. Vulnerabilities affecting this vendor skew toward serious outcomes—a meaningful share reach critical severity and frequently acquire public exploit code—and cluster in application-layer weakness classes including code injection, cross-site scripting, improper input validation, SQL injection, and authorization-bypass flaws that are typical of web applications handling untrusted user input and session control. Defenders should treat SMF instances as a patching priority, particularly internet-exposed or community-integrated deployments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
64
Total CVEs
More Total CVEs than 98% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Simplemachines over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2004
22 years ago
Most Recent CVE
Jul 14, 2026
11 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (64 CVEs).

64 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-4891CRITICAL
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
Jan 15, 20209.842NOYES
CVE-2022-26982HIGH
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by
Apr 5, 20227.238NOYES
CVE-2009-5068HIGH
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins"
Jan 15, 20207.233NOYES
CVE-2026-39903HIGH
Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a si
Jul 10, 20267.132NONO
CVE-2019-11574CRITICAL
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in
Mar 20, 20209.831NONO
CVE-2008-6971HIGH
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator
Aug 13, 20097.531NOYES
CVE-2026-61520HIGH
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated
Jul 14, 20267.730NONO
CVE-2011-1127HIGH
SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers to have an unspecified impact v
Jun 21, 201110.030NONO
CVE-2013-7466HIGH
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.
Mar 7, 20198.829NONO
CVE-2016-5726CRITICAL
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
Feb 9, 20179.829NONO
View all 64 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products64 CVEs
53%
39%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (31.3%)
Unknown44 (68.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (29.7%)
High1 (1.6%)
Unknown44 (68.8%)
User Interaction
None13 (20.3%)
Unknown44 (68.8%)
Required7 (10.9%)
Privileges Required
Low6 (9.4%)
High3 (4.7%)
None11 (17.2%)
Unknown44 (68.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (64 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
26.6% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Simplemachines.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Simplemachines — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Simplemachines's Products

View all 4 CNAs →

Top CWEs