vanillaforums records
26 published records for vendor vanillaforums.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.8%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2016-10073Weaponized | The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent mesvanillaforums · vanilla · CWE-200 | High7.5 | — | 83.6% | May 23, 2017 |
41Plan | CVE-2018-18903No exploit | Vanilla 2.6.x before 2.6.4 allows remote code execution.vanillaforums · vanilla · CWE-94 | Critical9.8 | — | 5.2% | Nov 3, 2018 |
40Plan | CVE-2011-3614No exploit | An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.vanillaforums · vanilla | Critical9.8 | — | 2.0% | Jan 22, 2020 |
32Monitor | CVE-2013-3528Proof of concept | Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related tovanillaforums · vanilla | High7.5 | — | 5.7% | May 10, 2013 |
32Monitor | CVE-2017-1000432Proof of concept | Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin accessvanillaforums · vanilla forums · CWE-352 | High8.0 | — | 1.6% | Jan 2, 2018 |
31Monitor | CVE-2013-3527Proof of concept | Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the pavanillaforums · vanilla · CWE-89 | High7.5 | — | 3.5% | May 10, 2013 |
31Monitor | CVE-2011-3613No exploit | An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.vanillaforums · vanilla · CWE-200 | High7.5 | — | 1.7% | Jan 22, 2020 |
29Monitor | CVE-2018-19499No exploit | Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unservanillaforums · vanilla · CWE-502 | High7.2 | — | 2.0% | Nov 23, 2018 |
26Monitor | CVE-2018-16410No exploit | Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/cvanillaforums · vanilla · CWE-89 | Medium6.5 | — | 0.9% | Sep 3, 2018 |
25Monitor | CVE-2011-0910No exploit | The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently vanillaforums · vanilla | Medium6.4 | — | 1.0% | Feb 8, 2011 |
24Monitor | CVE-2011-1009No exploit | Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.vanillaforums · vanilla · CWE-79 | Medium6.1 | — | 0.8% | Feb 5, 2020 |
24Monitor | CVE-2018-17571No exploit | Vanilla before 2.6.1 allows XSS via the email field of a profile.vanillaforums · vanilla · CWE-79 | Medium6.1 | — | 0.7% | Sep 28, 2018 |
24Monitor | CVE-2010-4264No exploit | It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute ovanillaforums · vanilla forums · CWE-79 | Medium6.1 | — | 0.7% | Jun 22, 2021 |
24Monitor | CVE-2010-4266No exploit | It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.vanillaforums · vanilla forums · CWE-601 | Medium6.1 | — | 0.6% | Jun 22, 2021 |
23Monitor | CVE-2011-0908No exploit | Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct pvanillaforums · vanilla · CWE-20 | Medium5.8 | — | 1.0% | Feb 8, 2011 |
22Monitor | CVE-2020-8825Proof of concept | index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.vanillaforums · vanilla · CWE-79 | Medium5.4 | — | 1.9% | Feb 10, 2020 |
21Monitor | CVE-2019-8279No exploit | Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.vanillaforums · vanilla forums · CWE-79 | Medium5.4 | — | 0.8% | Mar 1, 2019 |
20Monitor | CVE-2011-3812No exploit | Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pvanillaforums · vanilla · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
18Monitor | CVE-2012-6555Proof of concept | Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web vanillaforums · latestcomment · CWE-79 | Medium4.3 | — | 2.1% | May 23, 2013 |
18Monitor | CVE-2014-9685No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to injevanillaforums · vanilla · CWE-79 | Medium4.3 | — | 1.8% | Feb 25, 2015 |
17Monitor | CVE-2012-6557Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrarzodiacdm · aboutme-plugin · CWE-79 | Medium4.3 | — | 1.6% | May 23, 2013 |
17Monitor | CVE-2011-0526No exploit | Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web scriptvanillaforums · vanilla · CWE-79 | Medium4.3 | — | 1.3% | Feb 8, 2011 |
17Monitor | CVE-2018-15833No exploit | In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability ofvanillaforums · vanilla forums · CWE-639 | Medium4.3 | — | 0.9% | Aug 26, 2018 |
17Monitor | CVE-2011-0909No exploit | Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML vivanillaforums · vanilla · CWE-79 | Medium4.3 | — | 0.9% | Feb 8, 2011 |
14Monitor | CVE-2012-4954No exploit | The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing thvanillaforums · vanilla · CWE-264 | Low3.5 | — | 1.1% | Nov 15, 2012 |
- CVE-2016-1007355Plan
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent mes
HighCVSS 7.5WeaponizedEPSS 84%vanillaforums · vanillaMay 23, 2017
- CVE-2018-1890341Plan
Vanilla 2.6.x before 2.6.4 allows remote code execution.
CriticalCVSS 9.8No exploitEPSS 5%vanillaforums · vanillaNov 3, 2018
- CVE-2011-361440Plan
An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.
CriticalCVSS 9.8No exploitEPSS 2%vanillaforums · vanillaJan 22, 2020
- CVE-2013-352832Monitor
Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to
HighCVSS 7.5Proof of conceptEPSS 6%vanillaforums · vanillaMay 10, 2013
- CVE-2017-100043232Monitor
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
HighCVSS 8.0Proof of conceptEPSS 2%vanillaforums · vanilla forumsJan 2, 2018
- CVE-2013-352731Monitor
Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the pa
HighCVSS 7.5Proof of conceptEPSS 4%vanillaforums · vanillaMay 10, 2013
- CVE-2011-361331Monitor
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
HighCVSS 7.5No exploitEPSS 2%vanillaforums · vanillaJan 22, 2020
- CVE-2018-1949929Monitor
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unser
HighCVSS 7.2No exploitEPSS 2%vanillaforums · vanillaNov 23, 2018
- CVE-2018-1641026Monitor
Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/c
MediumCVSS 6.5No exploitEPSS 1%vanillaforums · vanillaSep 3, 2018
- CVE-2011-091025Monitor
The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently
MediumCVSS 6.4No exploitEPSS 1%vanillaforums · vanillaFeb 8, 2011
- CVE-2011-100924Monitor
Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.
MediumCVSS 6.1No exploitEPSS 1%vanillaforums · vanillaFeb 5, 2020
- CVE-2018-1757124Monitor
Vanilla before 2.6.1 allows XSS via the email field of a profile.
MediumCVSS 6.1No exploitEPSS 1%vanillaforums · vanillaSep 28, 2018
- CVE-2010-426424Monitor
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute o
MediumCVSS 6.1No exploitEPSS 1%vanillaforums · vanilla forumsJun 22, 2021
- CVE-2010-426624Monitor
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
MediumCVSS 6.1No exploitEPSS 1%vanillaforums · vanilla forumsJun 22, 2021
- CVE-2011-090823Monitor
Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct p
MediumCVSS 5.8No exploitEPSS 1%vanillaforums · vanillaFeb 8, 2011
- CVE-2020-882522Monitor
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
MediumCVSS 5.4Proof of conceptEPSS 2%vanillaforums · vanillaFeb 10, 2020
- CVE-2019-827921Monitor
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.
MediumCVSS 5.4No exploitEPSS 1%vanillaforums · vanilla forumsMar 1, 2019
- CVE-2011-381220Monitor
Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation p
MediumCVSS 5.0No exploitEPSS 1%vanillaforums · vanillaSep 23, 2011
- CVE-2012-655518Monitor
Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web
MediumCVSS 4.3Proof of conceptEPSS 2%vanillaforums · latestcommentMay 23, 2013
- CVE-2014-968518Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inje
MediumCVSS 4.3No exploitEPSS 2%vanillaforums · vanillaFeb 25, 2015
- CVE-2012-655717Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrar
MediumCVSS 4.3Proof of conceptEPSS 2%zodiacdm · aboutme-pluginMay 23, 2013
- CVE-2011-052617Monitor
Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3No exploitEPSS 1%vanillaforums · vanillaFeb 8, 2011
- CVE-2018-1583317Monitor
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of
MediumCVSS 4.3No exploitEPSS 1%vanillaforums · vanilla forumsAug 26, 2018
- CVE-2011-090917Monitor
Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3No exploitEPSS 1%vanillaforums · vanillaFeb 8, 2011
- CVE-2012-495414Monitor
The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing th
LowCVSS 3.5No exploitEPSS 1%vanillaforums · vanillaNov 15, 2012