Skip to content
Noroxi

vanillaforums records

26 published records for vendor vanillaforums.

All records

26 records
  • The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent mes

    HighCVSS 7.5WeaponizedEPSS 84%

    vanillaforums · vanillaMay 23, 2017

  • Vanilla 2.6.x before 2.6.4 allows remote code execution.

    CriticalCVSS 9.8No exploitEPSS 5%

    vanillaforums · vanillaNov 3, 2018

  • An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.

    CriticalCVSS 9.8No exploitEPSS 2%

    vanillaforums · vanillaJan 22, 2020

  • CVE-2013-3528
    32Monitor

    Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to

    HighCVSS 7.5Proof of conceptEPSS 6%

    vanillaforums · vanillaMay 10, 2013

  • Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access

    HighCVSS 8.0Proof of conceptEPSS 2%

    vanillaforums · vanilla forumsJan 2, 2018

  • CVE-2013-3527
    31Monitor

    Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the pa

    HighCVSS 7.5Proof of conceptEPSS 4%

    vanillaforums · vanillaMay 10, 2013

  • CVE-2011-3613
    31Monitor

    An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.

    HighCVSS 7.5No exploitEPSS 2%

    vanillaforums · vanillaJan 22, 2020

  • Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unser

    HighCVSS 7.2No exploitEPSS 2%

    vanillaforums · vanillaNov 23, 2018

  • Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/c

    MediumCVSS 6.5No exploitEPSS 1%

    vanillaforums · vanillaSep 3, 2018

  • CVE-2011-0910
    25Monitor

    The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently

    MediumCVSS 6.4No exploitEPSS 1%

    vanillaforums · vanillaFeb 8, 2011

  • CVE-2011-1009
    24Monitor

    Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    vanillaforums · vanillaFeb 5, 2020

  • Vanilla before 2.6.1 allows XSS via the email field of a profile.

    MediumCVSS 6.1No exploitEPSS 1%

    vanillaforums · vanillaSep 28, 2018

  • CVE-2010-4264
    24Monitor

    It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute o

    MediumCVSS 6.1No exploitEPSS 1%

    vanillaforums · vanilla forumsJun 22, 2021

  • CVE-2010-4266
    24Monitor

    It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.

    MediumCVSS 6.1No exploitEPSS 1%

    vanillaforums · vanilla forumsJun 22, 2021

  • CVE-2011-0908
    23Monitor

    Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct p

    MediumCVSS 5.8No exploitEPSS 1%

    vanillaforums · vanillaFeb 8, 2011

  • CVE-2020-8825
    22Monitor

    index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.

    MediumCVSS 5.4Proof of conceptEPSS 2%

    vanillaforums · vanillaFeb 10, 2020

  • CVE-2019-8279
    21Monitor

    Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.

    MediumCVSS 5.4No exploitEPSS 1%

    vanillaforums · vanilla forumsMar 1, 2019

  • CVE-2011-3812
    20Monitor

    Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation p

    MediumCVSS 5.0No exploitEPSS 1%

    vanillaforums · vanillaSep 23, 2011

  • CVE-2012-6555
    18Monitor

    Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web

    MediumCVSS 4.3Proof of conceptEPSS 2%

    vanillaforums · latestcommentMay 23, 2013

  • CVE-2014-9685
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inje

    MediumCVSS 4.3No exploitEPSS 2%

    vanillaforums · vanillaFeb 25, 2015

  • CVE-2012-6557
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrar

    MediumCVSS 4.3Proof of conceptEPSS 2%

    zodiacdm · aboutme-pluginMay 23, 2013

  • CVE-2011-0526
    17Monitor

    Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web script

    MediumCVSS 4.3No exploitEPSS 1%

    vanillaforums · vanillaFeb 8, 2011

  • In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of

    MediumCVSS 4.3No exploitEPSS 1%

    vanillaforums · vanilla forumsAug 26, 2018

  • CVE-2011-0909
    17Monitor

    Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML vi

    MediumCVSS 4.3No exploitEPSS 1%

    vanillaforums · vanillaFeb 8, 2011

  • CVE-2012-4954
    14Monitor

    The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing th

    LowCVSS 3.5No exploitEPSS 1%

    vanillaforums · vanillaNov 15, 2012