CVE-2025-12901
- EPSS 0.02%
- Veröffentlicht 12.11.2025 04:29:09
- Zuletzt bearbeitet 12.11.2025 16:19:12
The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing nonce validation on the set_subscription_level() function. This makes it possible for unauthenticat...
CVE-2025-11452
- EPSS 0.1%
- Veröffentlicht 08.11.2025 02:28:01
- Zuletzt bearbeitet 12.11.2025 16:19:59
The Asgaros Forum plugin for WordPress is vulnerable to SQL Injection via the '$_COOKIE['asgarosforum_unread_exclude']' cookie in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of suffici...
CVE-2025-39514
- EPSS 0.03%
- Veröffentlicht 16.04.2025 12:45:53
- Zuletzt bearbeitet 16.04.2025 13:25:37
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asgaros Asgaros Forum allows Stored XSS. This issue affects Asgaros Forum: from n/a through 3.0.0.
CVE-2025-32227
- EPSS 0.05%
- Veröffentlicht 10.04.2025 08:15:19
- Zuletzt bearbeitet 11.04.2025 15:39:52
Authentication Bypass by Spoofing vulnerability in Asgaros Asgaros Forum allows Identity Spoofing. This issue affects Asgaros Forum: from n/a through 3.0.0.
CVE-2024-32440
- EPSS 0.14%
- Veröffentlicht 15.04.2024 08:15:15
- Zuletzt bearbeitet 02.04.2025 15:02:15
Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.8.0.
CVE-2024-22284
- EPSS 0.62%
- Veröffentlicht 24.01.2024 12:15:57
- Zuletzt bearbeitet 21.11.2024 08:55:57
Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.
CVE-2023-5604
- EPSS 6.99%
- Veröffentlicht 27.11.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:42:06
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially l...
CVE-2022-41608
- EPSS 0.05%
- Veröffentlicht 22.05.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:23:29
Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum plugin <= 2.2.0 versions.
CVE-2022-0411
- EPSS 1.05%
- Veröffentlicht 28.02.2022 09:15:09
- Zuletzt bearbeitet 21.11.2024 06:38:34
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection
CVE-2021-25045
- EPSS 1.15%
- Veröffentlicht 24.01.2022 08:15:09
- Zuletzt bearbeitet 21.11.2024 05:54:14
The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL injection issue