Smf
Vendor:
First CVE: May 5, 2004 · Active for 22 years
16
Total CVEs
More Total CVEs than 89% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Smf over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2004
22 years ago
Most Recent CVE
Jul 14, 2026
13 days ago
CVE Severity & Scoring
Smf16 CVEs
38%
56%
All CVEs352,727 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network2 (12.5%)
Unknown14 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (12.5%)
High0 (0.0%)
Unknown14 (87.5%)
User Interaction
None2 (12.5%)
Unknown14 (87.5%)
Required0 (0.0%)
Privileges Required
Low2 (12.5%)
High0 (0.0%)
None0 (0.0%)
Unknown14 (87.5%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39903HIGH Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a si | Jul 10, 2026 | 7.1 | 32 | NO | NO |
CVE-2008-6971HIGH The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator | Aug 13, 2009 | 7.5 | 31 | NO | YES |
CVE-2026-61520HIGH Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated | Jul 14, 2026 | 7.7 | 30 | NO | NO |
CVE-2011-1127HIGH SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers to have an unspecified impact v | Jun 21, 2011 | 10.0 | 30 | NO | NO |
CVE-2009-2385HIGH SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to exe | Jul 8, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-2019HIGH Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA, which allows remote attackers | Apr 30, 2008 | 7.5 | 26 | NO | NO |
CVE-2004-1996MEDIUM Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag. | May 5, 2004 | 4.3 | 26 | NO | YES |
CVE-2012-5903MEDIUM Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.ph | Nov 17, 2012 | 4.3 | 25 | NO | YES |
CVE-2011-1130HIGH Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection attac | Jun 21, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-1128HIGH The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid login attempts, which might make it | Jun 21, 2011 | 7.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
25.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Smf
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0-beta3 | 1 | 7.5 | 7.1% | 0 | 1 |
| 2.0-beta2 | 1 | 7.5 | 7.1% | 0 | 1 |
| 2.0.2 | 1 | 4.3 | 1.6% | 0 | 1 |
| 2.0 | 8 | 6.9 | 1.3% | 0 | 1 |
| 1.1_rc3 | 1 | 6.8 | 1.4% | 0 | 0 |
| 1.1_final | 1 | 6.8 | 1.4% | 0 | 0 |
| 1.1.9 | 6 | 6.8 | 1.4% | 0 | 0 |
| 1.1.8 | 6 | 6.8 | 1.4% | 0 | 0 |
| 1.1.7 | 6 | 6.8 | 1.4% | 0 | 0 |
| 1.1.6 | 6 | 6.8 | 1.4% | 0 | 0 |
| 1.1.5 | 7 | 6.9 | 2.2% | 0 | 1 |
| 1.1.4 | 8 | 7.0 | 2.4% | 0 | 1 |
| 1.1.3 | 6 | 6.8 | 1.4% | 0 | 0 |
| 1.1.2 | 6 | 6.8 | 1.4% | 0 | 0 |
| 1.1.13 | 1 | 7.5 | 1.1% | 0 | 0 |
| 1.1.12 | 1 | 7.5 | 1.1% | 0 | 0 |
| 1.1.11 | 6 | 6.8 | 1.4% | 0 | 0 |
| 1.1.10 | 6 | 6.8 | 1.4% | 0 | 0 |
| 1.1.1 | 6 | 6.8 | 1.4% | 0 | 0 |
| 1.1 | 7 | 6.8 | 1.4% | 0 | 0 |