📦 Simple Machines Forum

by Simplemachines

🔍 What is Simple Machines Forum?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-26982

HIGH CVSS 7.2 Apr 5, 2022

This vulnerability allows remote authenticated administrators in SimpleMachinesForum to execute arbitrary PHP code by modifying themes. It affects SimpleMachinesForum versions 2.1.1 and earlier. The v...

CVE-2025-67163

MEDIUM CVSS 6.1 Dec 18, 2025

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to inject malicious scripts into the Forum Name parameter, which then executes in victims' browsers w...

CVE-2024-7438

MEDIUM CVSS 4.3 Aug 3, 2024

This vulnerability in SimpleMachines SMF 2.1.4 allows attackers to manipulate resource identifiers when reading user alerts, potentially leading to improper access to system resources. The attack can ...

CVE-2024-7437

MEDIUM CVSS 5.4 Aug 3, 2024

This critical vulnerability in SimpleMachines SMF 2.1.4 allows remote attackers to manipulate resource identifiers in the user alert deletion function, potentially enabling unauthorized actions. It af...