Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Vanillaforums Subscribe
Total 26 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-8279 1 Vanillaforums 1 Vanilla Forums 2019-03-04 3.5 LOW 5.4 MEDIUM
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.
CVE-2018-18903 1 Vanillaforums 1 Vanilla 2018-12-26 7.5 HIGH 9.8 CRITICAL
Vanilla 2.6.x before 2.6.4 allows remote code execution.
CVE-2018-17571 1 Vanillaforums 1 Vanilla 2018-11-15 4.3 MEDIUM 6.1 MEDIUM
Vanilla before 2.6.1 allows XSS via the email field of a profile.
CVE-2018-16410 1 Vanillaforums 1 Vanilla 2018-10-25 4.0 MEDIUM 6.5 MEDIUM
Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php.
CVE-2017-1000432 1 Vanillaforums 1 Vanilla Forums 2018-01-17 6.0 MEDIUM 8.0 HIGH
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
CVE-2011-3812 1 Vanillaforums 1 Vanilla 2012-05-20 5.0 MEDIUM N/A
Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Minify/min/utils.php and certain other files.