CVE-2023-32671: Buddyboss
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.
Affected products
- Buddyboss Buddyboss: version 2.2.9 only
Published 2023-10-03. Last modified 2026-06-17.