bmforum CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

bmforum vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to bmforum, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2008-6431 Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) outpused parameter to index.php, the (2) footer_copyright and (3) verandproname parameters to newtem/footer/bsd01footer.php, and the (4) topads and (5) myplugin parameters to newtem/header/bsd01header.php. [email protected] 4.3 0.98% 2009-03-06 2026-04-23
CVE-2008-6091 SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tagname parameter. [email protected] 6.8 0.41% 2009-02-09 2026-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence