Smf

Vendor:

First CVE: May 5, 2004 · Active for 22 years

16
Total CVEs
More Total CVEs than 89% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Smf over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2004
22 years ago
Most Recent CVE
Jul 14, 2026
13 days ago

CVE Severity & Scoring

Smf16 CVEs
All CVEs352,727 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network2 (12.5%)
Unknown14 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (12.5%)
High0 (0.0%)
Unknown14 (87.5%)
User Interaction
None2 (12.5%)
Unknown14 (87.5%)
Required0 (0.0%)
Privileges Required
Low2 (12.5%)
High0 (0.0%)
None0 (0.0%)
Unknown14 (87.5%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a si
Jul 10, 20267.132NONO
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator
Aug 13, 20097.531NOYES
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated
Jul 14, 20267.730NONO
SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers to have an unspecified impact v
Jun 21, 201110.030NONO
SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to exe
Jul 8, 20097.529NOYES
Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA, which allows remote attackers
Apr 30, 20087.526NONO
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.
May 5, 20044.326NOYES
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.ph
Nov 17, 20124.325NOYES
Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection attac
Jun 21, 20117.523NONO
The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid login attempts, which might make it
Jun 21, 20117.523NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
25.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Smf

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0-beta317.57.1%01
2.0-beta217.57.1%01
2.0.214.31.6%01
2.086.91.3%01
1.1_rc316.81.4%00
1.1_final16.81.4%00
1.1.966.81.4%00
1.1.866.81.4%00
1.1.766.81.4%00
1.1.666.81.4%00
1.1.576.92.2%01
1.1.487.02.4%01
1.1.366.81.4%00
1.1.266.81.4%00
1.1.1317.51.1%00
1.1.1217.51.1%00
1.1.1166.81.4%00
1.1.1066.81.4%00
1.1.166.81.4%00
1.176.81.4%00