Vanilla Forums
Vanillaforums · 7 CVEs
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
Jun 22, 2021
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitr…
Jun 22, 2021
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any me…
Mar 2, 2019
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, lead…
Aug 26, 2018
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
Jan 2, 2018
Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow rem…
Feb 25, 2015
The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile set…
Nov 15, 2012
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2010-4266 | It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher. | MEDIUM | 0.58% | Jun 22, 2021 |
| CVE-2010-4264 | It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side. | MEDIUM | 0.66% | Jun 22, 2021 |
| CVE-2019-8279 | Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum. | MEDIUM | 0.81% | Mar 2, 2019 |
| CVE-2018-15833 | In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to s… | MEDIUM | 0.88% | Aug 26, 2018 |
| CVE-2017-1000432 | Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access | HIGH | 1.65% | Jan 2, 2018 |
| CVE-2014-9685 | Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web sc… | MEDIUM | 1.77% | Feb 25, 2015 |
| CVE-2012-4954 | The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value duri… | LOW | 1.07% | Nov 15, 2012 |
Showing 1 to 7 of 7 CVEs