CVE-2023-32671: Buddyboss

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.

Affected products

Published 2023-10-03. Last modified 2026-06-17.