invisioncommunity kayıtları
invisioncommunity üreticisine ait 28 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %7,1
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %3,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-331 Insufficient Entropy1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
28 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2025-47916Silahlaştırılmış | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.invisioncommunity · invisioncommunity · CWE-1336 | Kritik9,8 | — | %83,7 | 16 May 2025 |
48Planlayın | CVE-2012-5692Silahlaştırılmış | Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impacinvisioncommunity · invision power board | Kritik10,0 | — | %26,0 | 31 Eki 2012 |
42Planlayın | CVE-2024-30163Kavram kanıtı | Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\invisioncommunity · invisioncommunity · CWE-89 | Kritik9,8 | — | %8,7 | 7 Haz 2024 |
41Planlayın | CVE-2021-32924İstismar yok | Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\frinvisioncommunity · ips community suite · CWE-94 | Yüksek8,8 | — | %19,9 | 1 Haz 2021 |
41Planlayın | CVE-2012-2226Kavram kanıtı | Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information oinvisioncommunity · invision power board · CWE-434 | Kritik9,8 | — | %7,4 | 9 Oca 2020 |
40Planlayın | CVE-2017-8898İstismar yok | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from ainvisioncommunity · invision power board · CWE-79 | Kritik9,8 | — | %1,9 | 11 May 2017 |
40Planlayın | CVE-2013-3725İstismar yok | Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.invisioncommunity · invision power board | Kritik9,8 | — | %1,8 | 12 Şub 2020 |
36İzleyin | CVE-2016-6174Kavram kanıtı | applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Bphp · php | Yüksek8,1 | — | %12,3 | 12 Tem 2016 |
36İzleyin | CVE-2021-40604İstismar yok | A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrarinvisioncommunity · ips community suite · CWE-918 | Kritik9,1 | — | %1,2 | 13 Haz 2022 |
35İzleyin | CVE-2021-3025İstismar yok | Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popinvisioncommunity · ips community suite · CWE-89 | Yüksek8,8 | — | %1,4 | 8 Oca 2021 |
35İzleyin | CVE-2014-4928İstismar yok | SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL comminvisioncommunity · invision power board · CWE-89 | Yüksek8,8 | — | %1,1 | 20 Mar 2018 |
32İzleyin | CVE-2017-8899İstismar yok | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the atinvisioncommunity · invision power board · CWE-79 | Yüksek8,1 | — | %1,5 | 11 May 2017 |
31İzleyin | CVE-2015-6812İstismar yok | Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to causeinvisioncommunity · invision power board · CWE-399 | Yüksek7,8 | — | %1,4 | 4 Eyl 2015 |
30İzleyin | CVE-2014-9239İstismar yok | SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3invisioncommunity · invision power board · CWE-89 | Yüksek7,5 | — | %1,4 | 3 Ara 2014 |
30İzleyin | CVE-2009-3974İstismar yok | Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute ainvisioncommunity · invision power board · CWE-89 | Yüksek7,5 | — | %1,0 | 18 Kas 2009 |
28İzleyin | CVE-2024-30162İstismar yok | Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\aCWE-345 | Yüksek7,2 | — | %0,7 | 7 Haz 2024 |
25İzleyin | CVE-2009-5159İstismar yok | Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.invisioncommunity · invision power board · CWE-79 | Orta6,1 | — | %3,5 | 13 Mar 2020 |
25İzleyin | CVE-2019-8278İstismar yok | Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.invisioncommunity · invision power board · CWE-79 | Orta6,1 | — | %1,9 | 1 Mar 2019 |
24İzleyin | CVE-2017-8897İstismar yok | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/conveinvisioncommunity · invision power board · CWE-79 | Orta6,1 | — | %1,2 | 11 May 2017 |
24İzleyin | CVE-2021-39249İstismar yok | Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become invisioncommunity · invision power board · CWE-330 | Orta6,1 | — | %0,8 | 17 Ağu 2021 |
24İzleyin | CVE-2021-3026İstismar yok | Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment.invisioncommunity · ips community suite · CWE-79 | Orta6,1 | — | %0,6 | 5 Oca 2021 |
23İzleyin | CVE-2016-2564İstismar yok | Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the morinvisioncommunity · invision power board · CWE-331 | Orta5,9 | — | %1,3 | 23 Nis 2017 |
21İzleyin | CVE-2021-39250İstismar yok | Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploadeinvisioncommunity · invision power board · CWE-79 | Orta5,4 | — | %0,8 | 17 Ağu 2021 |
19İzleyin | CVE-2020-29477Kavram kanıtı | Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field.invisioncommunity · community · CWE-79 | Orta4,8 | — | %1,1 | 30 Ara 2020 |
18İzleyin | CVE-2014-3149İstismar yok | Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded beinvisioncommunity · invision power board · CWE-79 | Orta4,3 | — | %1,9 | 3 Tem 2014 |
- CVE-2025-4791664Bu hafta
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.
KritikCVSS 9,8SilahlaştırılmışEPSS %84invisioncommunity · invisioncommunity16 May 2025
- CVE-2012-569248Planlayın
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impac
KritikCVSS 10,0SilahlaştırılmışEPSS %26invisioncommunity · invision power board31 Eki 2012
- CVE-2024-3016342Planlayın
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\
KritikCVSS 9,8Kavram kanıtıEPSS %9invisioncommunity · invisioncommunity7 Haz 2024
- CVE-2021-3292441Planlayın
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\fr
YüksekCVSS 8,8İstismar yokEPSS %20invisioncommunity · ips community suite1 Haz 2021
- CVE-2012-222641Planlayın
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information o
KritikCVSS 9,8Kavram kanıtıEPSS %7invisioncommunity · invision power board9 Oca 2020
- CVE-2017-889840Planlayın
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from a
KritikCVSS 9,8İstismar yokEPSS %2invisioncommunity · invision power board11 May 2017
- CVE-2013-372540Planlayın
Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
KritikCVSS 9,8İstismar yokEPSS %2invisioncommunity · invision power board12 Şub 2020
- CVE-2016-617436İzleyin
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power B
YüksekCVSS 8,1Kavram kanıtıEPSS %12php · php12 Tem 2016
- CVE-2021-4060436İzleyin
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrar
KritikCVSS 9,1İstismar yokEPSS %1invisioncommunity · ips community suite13 Haz 2022
- CVE-2021-302535İzleyin
Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=pop
YüksekCVSS 8,8İstismar yokEPSS %1invisioncommunity · ips community suite8 Oca 2021
- CVE-2014-492835İzleyin
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL comm
YüksekCVSS 8,8İstismar yokEPSS %1invisioncommunity · invision power board20 Mar 2018
- CVE-2017-889932İzleyin
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the at
YüksekCVSS 8,1İstismar yokEPSS %1invisioncommunity · invision power board11 May 2017
- CVE-2015-681231İzleyin
Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause
YüksekCVSS 7,8İstismar yokEPSS %1invisioncommunity · invision power board4 Eyl 2015
- CVE-2014-923930İzleyin
SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3
YüksekCVSS 7,5İstismar yokEPSS %1invisioncommunity · invision power board3 Ara 2014
- CVE-2009-397430İzleyin
Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute a
YüksekCVSS 7,5İstismar yokEPSS %1invisioncommunity · invision power board18 Kas 2009
- CVE-2024-3016228İzleyin
Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\a
YüksekCVSS 7,2İstismar yokEPSS %17 Haz 2024
- CVE-2009-515925İzleyin
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
OrtaCVSS 6,1İstismar yokEPSS %3invisioncommunity · invision power board13 Mar 2020
- CVE-2019-827825İzleyin
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
OrtaCVSS 6,1İstismar yokEPSS %2invisioncommunity · invision power board1 Mar 2019
- CVE-2017-889724İzleyin
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/conve
OrtaCVSS 6,1İstismar yokEPSS %1invisioncommunity · invision power board11 May 2017
- CVE-2021-3924924İzleyin
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become
OrtaCVSS 6,1İstismar yokEPSS %1invisioncommunity · invision power board17 Ağu 2021
- CVE-2021-302624İzleyin
Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment.
OrtaCVSS 6,1İstismar yokEPSS %1invisioncommunity · ips community suite5 Oca 2021
- CVE-2016-256423İzleyin
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the mor
OrtaCVSS 5,9İstismar yokEPSS %1invisioncommunity · invision power board23 Nis 2017
- CVE-2021-3925021İzleyin
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploade
OrtaCVSS 5,4İstismar yokEPSS %1invisioncommunity · invision power board17 Ağu 2021
- CVE-2020-2947719İzleyin
Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field.
OrtaCVSS 4,8Kavram kanıtıEPSS %1invisioncommunity · community30 Ara 2020
- CVE-2014-314918İzleyin
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded be
OrtaCVSS 4,3İstismar yokEPSS %2invisioncommunity · invision power board3 Tem 2014