Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vanilla Forums MEDIUM 6.1
CVE-2010-4264

It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the cli…

Fix: 2.0.10+
Fix from $1,600 2021-06-22
Vanilla Forums MEDIUM 6.1
CVE-2010-4266

It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.

Fix: 2.0.10+
Fix from $1,600 2021-06-22
Vanilla MEDIUM 5.4
CVE-2020-8825

index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.

No fix yet
Fix from $1,600 2020-02-10
Vanilla MEDIUM 6.1
CVE-2011-1009

Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.

Fix: after 2.0.17.5
Fix from $1,600 2020-02-05
Vanilla CRITICAL 9.8
CVE-2011-3614

An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.

Fix: 2.0.17.9+
Fix from $2,300 2020-01-22
Vanilla HIGH 7.5
CVE-2011-3613

An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.

Fix: 2.0.17.9+
Fix from $1,950 2020-01-22
Vanilla Forums MEDIUM 5.4
CVE-2019-8279

Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.

Fix: 2.5.0+
Fix from $1,600 2019-03-02
Vanilla HIGH 7.2
CVE-2018-19499

Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in…

Fix: 2.5.5 / 2.6.2+
Fix from $1,950 2018-11-23
Vanilla CRITICAL 9.8
CVE-2018-18903EPSS 5%

Vanilla 2.6.x before 2.6.4 allows remote code execution.

Fix: 2.6.4+
Fix from $2,300 2018-11-03
Vanilla MEDIUM 6.1
CVE-2018-17571

Vanilla before 2.6.1 allows XSS via the email field of a profile.

Fix: 2.6.1+
Fix from $1,600 2018-09-28
Vanilla MEDIUM 6.5
CVE-2018-16410

Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invi…

Patch available
Fix from $1,600 2018-09-03
Vanilla Forums HIGH 8.0
CVE-2017-1000432

Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access

Fix: 2.1.5+
Fix from $1,950 2018-01-02
Vanilla HIGH 7.5
CVE-2016-10073EPSS 84%

The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and…

Fix: after 2.3.0
Fix from $1,950 2017-05-23
Vanilla HIGH 7.5
CVE-2013-3527

Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter n…

Fix: after 2.0.18.7
Fix from $1,950 2013-05-10
Vanilla HIGH 7.5
CVE-2013-3528EPSS 6%

Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object …

Fix: after 2.0.18.7
Fix from $1,950 2013-05-10
Vanilla MEDIUM 5.0
CVE-2011-3812

Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an…

Mitigation only
Fix from $1,600 2011-09-24
Vanilla MEDIUM 6.4
CVE-2011-0910

The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain ac…

Fix: after 2.0.17.5
Fix from $1,600 2011-02-08
Vanilla MEDIUM 5.8
CVE-2011-0908

Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing a…

Fix: after 2.0.17.5
Fix from $1,600 2011-02-08