Vulnerabilities (CVE)

Filtered by vendor Jforum Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40509 1 Jforum 1 Jforum 2021-09-09 3.5 LOW 5.4 MEDIUM
ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.
CVE-2019-7550 1 Jforum 1 Jforum 2020-08-24 5.0 MEDIUM 5.3 MEDIUM
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product is discontinued.