Simple Machines develops and maintains Simple Machines Forum (SMF), a widely embedded open-source discussion-board platform that powers community sections across many websites, alongside integrations with e-commerce systems such as OpenCart. Despite a narrow product portfolio, the vendor's vulnerability footprint is prominent in the landscape due to SMF's broad deployment and longevity as a self-hosted application. Vulnerabilities affecting this vendor skew toward serious outcomes—a meaningful share reach critical severity and frequently acquire public exploit code—and cluster in application-layer weakness classes including code injection, cross-site scripting, improper input validation, SQL injection, and authorization-bypass flaws that are typical of web applications handling untrusted user input and session control. Defenders should treat SMF instances as a patching priority, particularly internet-exposed or community-integrated deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simplemachines over time
Signals from CVEs in this vendor scope (64 CVEs).
64 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4891CRITICAL Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements. | Jan 15, 2020 | 9.8 | 42 | NO | YES |
CVE-2022-26982HIGH SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by | Apr 5, 2022 | 7.2 | 38 | NO | YES |
CVE-2009-5068HIGH There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" | Jan 15, 2020 | 7.2 | 33 | NO | YES |
CVE-2026-39903HIGH Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a si | Jul 10, 2026 | 7.1 | 32 | NO | NO |
CVE-2019-11574CRITICAL An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in | Mar 20, 2020 | 9.8 | 31 | NO | NO |
CVE-2008-6971HIGH The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator | Aug 13, 2009 | 7.5 | 31 | NO | YES |
CVE-2026-61520HIGH Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated | Jul 14, 2026 | 7.7 | 30 | NO | NO |
CVE-2011-1127HIGH SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers to have an unspecified impact v | Jun 21, 2011 | 10.0 | 30 | NO | NO |
CVE-2013-7466HIGH Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install. | Mar 7, 2019 | 8.8 | 29 | NO | NO |
CVE-2016-5726CRITICAL Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter. | Feb 9, 2017 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (64 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simplemachines.
Media articles that mention a CVE ID that affects a product developed by Simplemachines — matched by CVE ID, not by vendor name.