Known Vulnerabilities for BuddyPress by Buddypress
Listed below are 10 of the newest known vulnerabilities associated with "BuddyPress" by "Buddypress".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66592 json | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-59551 json | Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-59549 json | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-53675 json | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenti... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53674 json | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username ... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53673 json | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticat... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-40773 json | Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-15287 json | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the orde... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-13450 json | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vul... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-8155 json | The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, all... | Not Provided | 2026-07-31 | 2026-07-31 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Buddypress | Buddypress | 5.1.2 | |||
| Application | Buddypress | Buddypress | 3.0 | |||
| Application | Buddypress | Buddypress | 2.9.3 | |||
| Application | Buddypress | Buddypress | 2.9.2 | |||
| Application | Buddypress | Buddypress | 2.9.0 | |||
| Application | Buddypress | Buddypress | 2.9.0 | |||
| Application | Buddypress | Buddypress | 2.8.1 | |||
| Application | Buddypress | Buddypress | 2.8.0 | |||
| Application | Buddypress | Buddypress | 2.8.0 | |||
| Application | Buddypress | Buddypress | 2.7.4 | |||
| Application | Buddypress | Buddypress | 2.7.1 | |||
| Application | Buddypress | Buddypress | 2.7.0 | |||
| Application | Buddypress | Buddypress | 2.7.0 | |||
| Application | Buddypress | Buddypress | 2.7.0 | |||
| Application | Buddypress | Buddypress | 2.5.0 | |||
| Application | Buddypress | Buddypress | 2.4.2 | |||
| Application | Buddypress | Buddypress | 2.4.0 | |||
| Application | Buddypress | Buddypress | 2.3.5 | |||
| Application | Buddypress | Buddypress | 2.3.4 | |||
| Application | Buddypress | Buddypress | 2.3.3 |