Known vulnerabilities in the Buddyboss Platform plugin
9 security advisories have been published for the Buddyboss Platform plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Buddyboss Platform - SQL Injection (CVE-2026-59514) CRITICAL
- Buddyboss Platform - PHP Object Injection (CVE-2026-56032) CRITICAL
- Buddyboss Platform - Security Vulnerability (CVE-2024-12767) LOW
- Buddyboss Platform - Authentication Bypass (CVE-2025-1909) CRITICAL
- Buddyboss Platform - Cross-Site Scripting (XSS) (CVE-2024-13860) MEDIUM
- Buddyboss Platform - Cross-Site Scripting (XSS) (CVE-2024-13859) MEDIUM
- Buddyboss Platform - Cross-Site Scripting (XSS) (CVE-2024-13858) MEDIUM
- Buddyboss Platform - Cross-Site Scripting (XSS) (CVE-2024-13402) MEDIUM
- Buddyboss Platform - Security Vulnerability (CVE-2024-4750) MEDIUM