Neoforum
Neoforum has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; none of them are fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 6.1 out of 10. 2026 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include SQL Injection.
None of the 2 issues recorded for Neoforum have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Mrreee. The current release is tested up to WordPress 5.0.27.
CVE-2026-24623Neoforum <= 1.0 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Neoforum
Author
saeros1984
Neoforum is full-fledged forum engine for WordPress, including all standard forum functionality. Currently available features Full-fledged forum engine, can be used for communities of any size. Super responsive forum on all kind of devices. Built-in forum/topic subscription. Drag and Drop forum management system. Topic and Post front-end moderation. Four moderators ranks with different rights. Can be enabled: Premoderation of new topics. Marking topics as solved. Switching on/off links in forum posts. User files attachment. Guests can be allowed to reply in topics. Forum topics and posts Read / Unread logging. WordPress .MO/.PO translation files.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C