Home/Product/socialengine
Product

socialengine

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-41461
<= 7.8.0
SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint
8.5HIGH
CVE-2026-41460
<= 7.8.0
SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where us
9.8CRITICAL
CVE-2012-6721
< 4.2.4
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngin
6.3MEDIUM
CVE-2012-6720
< 4.2.4
Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web sc
6.1MEDIUM
CVE-2008-6121
<= 2.7
CRLF injection vulnerability in SocialEngine (SE) 2.7 and earlier allows remote attackers to inject arbitrary HTTP headers and con
CVE-2008-6120
<= 2.7
SQL injection vulnerability in profile_comments.php in SocialEngine (SE) 2.7 and earlier allows remote attackers to execute arbitr
CVE-2009-0400
all versions
SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via t
CVE-2008-3298
<= 2.81
SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to e
CVE-2008-3297
<= 2.81
Multiple SQL injection vulnerabilities in SocialEngine (SE) before 2.83 allow remote attackers to execute arbitrary SQL commands v
CVE-2007-6581
all versions
Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local fi
threatengine.sh