İçeriğe atla
Noroxi

invisioncommunity kayıtları

invisioncommunity üreticisine ait 28 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
2 · %7,1
Pre-auth RCE
6
Düzeltme kaydı olan
%3,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

28 kayıt
  • CVE-2025-47916
    64Bu hafta

    Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.

    KritikCVSS 9,8SilahlaştırılmışEPSS %84

    invisioncommunity · invisioncommunity16 May 2025

  • CVE-2012-5692
    48Planlayın

    Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impac

    KritikCVSS 10,0SilahlaştırılmışEPSS %26

    invisioncommunity · invision power board31 Eki 2012

  • CVE-2024-30163
    42Planlayın

    Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    invisioncommunity · invisioncommunity7 Haz 2024

  • CVE-2021-32924
    41Planlayın

    Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\fr

    YüksekCVSS 8,8İstismar yokEPSS %20

    invisioncommunity · ips community suite1 Haz 2021

  • CVE-2012-2226
    41Planlayın

    Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information o

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    invisioncommunity · invision power board9 Oca 2020

  • CVE-2017-8898
    40Planlayın

    Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from a

    KritikCVSS 9,8İstismar yokEPSS %2

    invisioncommunity · invision power board11 May 2017

  • CVE-2013-3725
    40Planlayın

    Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.

    KritikCVSS 9,8İstismar yokEPSS %2

    invisioncommunity · invision power board12 Şub 2020

  • CVE-2016-6174
    36İzleyin

    applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power B

    YüksekCVSS 8,1Kavram kanıtıEPSS %12

    php · php12 Tem 2016

  • CVE-2021-40604
    36İzleyin

    A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrar

    KritikCVSS 9,1İstismar yokEPSS %1

    invisioncommunity · ips community suite13 Haz 2022

  • CVE-2021-3025
    35İzleyin

    Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=pop

    YüksekCVSS 8,8İstismar yokEPSS %1

    invisioncommunity · ips community suite8 Oca 2021

  • CVE-2014-4928
    35İzleyin

    SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL comm

    YüksekCVSS 8,8İstismar yokEPSS %1

    invisioncommunity · invision power board20 Mar 2018

  • CVE-2017-8899
    32İzleyin

    Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the at

    YüksekCVSS 8,1İstismar yokEPSS %1

    invisioncommunity · invision power board11 May 2017

  • CVE-2015-6812
    31İzleyin

    Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause

    YüksekCVSS 7,8İstismar yokEPSS %1

    invisioncommunity · invision power board4 Eyl 2015

  • CVE-2014-9239
    30İzleyin

    SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3

    YüksekCVSS 7,5İstismar yokEPSS %1

    invisioncommunity · invision power board3 Ara 2014

  • CVE-2009-3974
    30İzleyin

    Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute a

    YüksekCVSS 7,5İstismar yokEPSS %1

    invisioncommunity · invision power board18 Kas 2009

  • CVE-2024-30162
    28İzleyin

    Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\a

    YüksekCVSS 7,2İstismar yokEPSS %1

    7 Haz 2024

  • CVE-2009-5159
    25İzleyin

    Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.

    OrtaCVSS 6,1İstismar yokEPSS %3

    invisioncommunity · invision power board13 Mar 2020

  • CVE-2019-8278
    25İzleyin

    Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.

    OrtaCVSS 6,1İstismar yokEPSS %2

    invisioncommunity · invision power board1 Mar 2019

  • CVE-2017-8897
    24İzleyin

    Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/conve

    OrtaCVSS 6,1İstismar yokEPSS %1

    invisioncommunity · invision power board11 May 2017

  • CVE-2021-39249
    24İzleyin

    Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become

    OrtaCVSS 6,1İstismar yokEPSS %1

    invisioncommunity · invision power board17 Ağu 2021

  • CVE-2021-3026
    24İzleyin

    Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment.

    OrtaCVSS 6,1İstismar yokEPSS %1

    invisioncommunity · ips community suite5 Oca 2021

  • CVE-2016-2564
    23İzleyin

    Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the mor

    OrtaCVSS 5,9İstismar yokEPSS %1

    invisioncommunity · invision power board23 Nis 2017

  • CVE-2021-39250
    21İzleyin

    Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploade

    OrtaCVSS 5,4İstismar yokEPSS %1

    invisioncommunity · invision power board17 Ağu 2021

  • CVE-2020-29477
    19İzleyin

    Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field.

    OrtaCVSS 4,8Kavram kanıtıEPSS %1

    invisioncommunity · community30 Ara 2020

  • CVE-2014-3149
    18İzleyin

    Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded be

    OrtaCVSS 4,3İstismar yokEPSS %2

    invisioncommunity · invision power board3 Tem 2014