29-12-2025 10:39, 10:39
Yes — Simple Machines Forum (SMF) 2.1.6 does have at least one known, documented vulnerability and is likely affected by others reported for that codebase or earlier versions. Here’s a summary of what’s known as of late 2025:
? 1. CVE-2025-67163 — Stored Cross-Site Scripting (XSS)
A stored XSS vulnerability exists in SMF 2.1.6 specifically via the “Forum Name” parameter.
This allows an attacker to submit crafted input that is stored and later rendered in pages viewed by other users, potentially executing arbitrary JavaScript/HTML in victims’ browsers. �
cvedetails.com +1
The severity is medium (CVSS ~6.1) and the exploit doesn’t require authentication.
? 1. CVE-2025-67163 — Stored Cross-Site Scripting (XSS)
A stored XSS vulnerability exists in SMF 2.1.6 specifically via the “Forum Name” parameter.
This allows an attacker to submit crafted input that is stored and later rendered in pages viewed by other users, potentially executing arbitrary JavaScript/HTML in victims’ browsers. �
cvedetails.com +1
The severity is medium (CVSS ~6.1) and the exploit doesn’t require authentication.


