CVE-2023-32669: Buddyboss

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).

Affected products

Published 2023-10-03. Last modified 2026-06-17.