İçeriğe atla
Noroxi

vanillaforums kayıtları

vanillaforums üreticisine ait 26 yayımlanmış kayıt.

Tüm kayıtlar

26 kayıt
  • CVE-2016-10073
    55Planlayın

    The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent mes

    YüksekCVSS 7,5SilahlaştırılmışEPSS %84

    vanillaforums · vanilla23 May 2017

  • CVE-2018-18903
    41Planlayın

    Vanilla 2.6.x before 2.6.4 allows remote code execution.

    KritikCVSS 9,8İstismar yokEPSS %5

    vanillaforums · vanilla3 Kas 2018

  • CVE-2011-3614
    40Planlayın

    An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.

    KritikCVSS 9,8İstismar yokEPSS %2

    vanillaforums · vanilla22 Oca 2020

  • CVE-2013-3528
    32İzleyin

    Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to

    YüksekCVSS 7,5Kavram kanıtıEPSS %6

    vanillaforums · vanilla10 May 2013

  • Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access

    YüksekCVSS 8,0Kavram kanıtıEPSS %2

    vanillaforums · vanilla forums2 Oca 2018

  • CVE-2013-3527
    31İzleyin

    Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the pa

    YüksekCVSS 7,5Kavram kanıtıEPSS %4

    vanillaforums · vanilla10 May 2013

  • CVE-2011-3613
    31İzleyin

    An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.

    YüksekCVSS 7,5İstismar yokEPSS %2

    vanillaforums · vanilla22 Oca 2020

  • CVE-2018-19499
    29İzleyin

    Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unser

    YüksekCVSS 7,2İstismar yokEPSS %2

    vanillaforums · vanilla23 Kas 2018

  • CVE-2018-16410
    26İzleyin

    Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/c

    OrtaCVSS 6,5İstismar yokEPSS %1

    vanillaforums · vanilla3 Eyl 2018

  • CVE-2011-0910
    25İzleyin

    The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently

    OrtaCVSS 6,4İstismar yokEPSS %1

    vanillaforums · vanilla8 Şub 2011

  • CVE-2011-1009
    24İzleyin

    Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    vanillaforums · vanilla5 Şub 2020

  • CVE-2018-17571
    24İzleyin

    Vanilla before 2.6.1 allows XSS via the email field of a profile.

    OrtaCVSS 6,1İstismar yokEPSS %1

    vanillaforums · vanilla28 Eyl 2018

  • CVE-2010-4264
    24İzleyin

    It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute o

    OrtaCVSS 6,1İstismar yokEPSS %1

    vanillaforums · vanilla forums22 Haz 2021

  • CVE-2010-4266
    24İzleyin

    It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.

    OrtaCVSS 6,1İstismar yokEPSS %1

    vanillaforums · vanilla forums22 Haz 2021

  • CVE-2011-0908
    23İzleyin

    Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct p

    OrtaCVSS 5,8İstismar yokEPSS %1

    vanillaforums · vanilla8 Şub 2011

  • CVE-2020-8825
    22İzleyin

    index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.

    OrtaCVSS 5,4Kavram kanıtıEPSS %2

    vanillaforums · vanilla10 Şub 2020

  • CVE-2019-8279
    21İzleyin

    Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.

    OrtaCVSS 5,4İstismar yokEPSS %1

    vanillaforums · vanilla forums1 Mar 2019

  • CVE-2011-3812
    20İzleyin

    Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation p

    OrtaCVSS 5,0İstismar yokEPSS %1

    vanillaforums · vanilla23 Eyl 2011

  • CVE-2012-6555
    18İzleyin

    Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    vanillaforums · latestcomment23 May 2013

  • CVE-2014-9685
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inje

    OrtaCVSS 4,3İstismar yokEPSS %2

    vanillaforums · vanilla25 Şub 2015

  • CVE-2012-6557
    17İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrar

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    zodiacdm · aboutme-plugin23 May 2013

  • CVE-2011-0526
    17İzleyin

    Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web script

    OrtaCVSS 4,3İstismar yokEPSS %1

    vanillaforums · vanilla8 Şub 2011

  • CVE-2018-15833
    17İzleyin

    In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of

    OrtaCVSS 4,3İstismar yokEPSS %1

    vanillaforums · vanilla forums26 Ağu 2018

  • CVE-2011-0909
    17İzleyin

    Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML vi

    OrtaCVSS 4,3İstismar yokEPSS %1

    vanillaforums · vanilla8 Şub 2011

  • CVE-2012-4954
    14İzleyin

    The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing th

    DüşükCVSS 3,5İstismar yokEPSS %1

    vanillaforums · vanilla15 Kas 2012