CVE-2013-7234: Simplemachines Simple Machines Forum

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.

Affected products

  • Simplemachines Simple Machines Forum: up to and including 1.1.9; version 1.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; …

Published 2014-04-29. Last modified 2026-06-17.