Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-47916EPSS 84% Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeed… Invisioncommunity 5.0.7+ Fix from $2,3002025-05-16 CRITICAL 9.8 CVE-2024-30163EPSS 9% Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_… Invisioncommunity 4.7.16+ Fix from $2,3002024-06-07 CRITICAL 9.1 CVE-2021-40604 A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or… Ips Community Suite 4.6.2+ Fix from $2,3002022-06-13 MEDIUM 6.1 CVE-2021-39249 Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictab… Invision Power Board 4.6.5.1+ Fix from $1,6002021-08-17 MEDIUM 5.4 CVE-2021-39250 Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file ca… Invision Power Board 4.6.5.1+ Fix from $1,6002021-08-17 HIGH 8.8 CVE-2021-32924EPSS 20% Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages… Ips Community Suite 4.6.0+ Fix from $1,9502021-06-01 HIGH 8.8 CVE-2021-3025 Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular acti… Ips Community Suite 4.5.4.2+ Fix from $1,9502021-01-08 MEDIUM 6.1 CVE-2021-3026 Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment. Ips Community Suite 4.5.4.2+ Fix from $1,6002021-01-05 MEDIUM 6.1 CVE-2009-5159 Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment. Invision Power Board after 3.0.4 Fix from $1,6002020-03-13 CRITICAL 9.8 CVE-2013-3725 Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution. Invision Power Board 4.0.0+ Fix from $2,3002020-02-12 CRITICAL 9.8 CVE-2012-2226EPSS 7% Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute… Invision Power Board 3.3.1+ Fix from $2,3002020-01-09 MEDIUM 6.1 CVE-2019-8278 Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution. Invision Power Board after 3.4.8 Fix from $1,6002019-03-02 HIGH 8.8 CVE-2014-4928 SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via … Invision Power Board 3.4.6+ Fix from $1,9502018-03-20 CRITICAL 9.8 CVE-2017-8898 Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invisio… Invision Power Board after 4.1.19.2 Fix from $2,3002017-05-11 HIGH 8.1 CVE-2017-8899 Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments… Invision Power Board after 4.1.19.2 Fix from $1,9502017-05-11 MEDIUM 6.1 CVE-2017-8897 Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/in… Invision Power Board after 4.1.19.2 Fix from $1,6002017-05-11 MEDIUM 5.9 CVE-2016-2564 Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy… Invision Power Board after 4.1.8.1 Fix from $1,6002017-04-23 HIGH 7.8 CVE-2015-6812 Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial… Invision Power Board after 4.0.11 Fix from $1,9502015-09-04 HIGH 7.5 CVE-2014-9239 SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and … Invision Power Board Patch available Fix from $1,9502014-12-03 HIGH 10.0 CVE-2012-5692EPSS 26% Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and rem… Invision Power Board Patch available Fix from $1,9502012-10-31 HIGH 7.5 CVE-2009-3974 Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute arbitrary … Invision Power Board Patch available Fix from $1,9502009-11-18