Buddyforms
Vendor:
First CVE: Aug 27, 2019 · Active for 6 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Buddyforms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 27, 2019
6 years ago
Most Recent CVE
Oct 27, 2025
270 days ago
CVE Severity & Scoring
Buddyforms11 CVEs
55%
27%
18%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (72.7%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None6 (54.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26326CRITICAL The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issu | Feb 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2018-21003CRITICAL The buddyforms plugin before 2.2.8 for WordPress has SQL injection. | Aug 27, 2019 | 9.8 | 28 | NO | NO |
CVE-2024-8246HIGH The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in | Sep 14, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-32151HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyforms allows PHP Local File Incl | Apr 4, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-32830HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.Th | May 17, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-62973MEDIUM Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyForms: from n/a thro | Oct 27, 2025 | 5.3 | 19 | NO | NO |
CVE-2024-30198MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeKraft BuddyForms allows Reflected XSS.This issue affects BuddyForms: from | Mar 27, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-47377MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themekraft BuddyForms buddyforms allows Stored XSS.This issue affects BuddyFor | Oct 5, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-5149MEDIUM The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. | Jun 5, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-12038MEDIUM The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scrip | Feb 22, 2025 | 5.4 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Buddyforms
Top CWEs
Versions
No cataloged versions.