Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2010-4264 It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the cli… Vanilla Forums 2.0.10+ Fix from $1,6002021-06-22 MEDIUM 6.1 CVE-2010-4266 It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher. Vanilla Forums 2.0.10+ Fix from $1,6002021-06-22 MEDIUM 5.4 CVE-2020-8825 index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. Vanilla No fix yet Fix from $1,6002020-02-10 MEDIUM 6.1 CVE-2011-1009 Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter. Vanilla after 2.0.17.5 Fix from $1,6002020-02-05 CRITICAL 9.8 CVE-2011-3614 An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9. Vanilla 2.0.17.9+ Fix from $2,3002020-01-22 HIGH 7.5 CVE-2011-3613 An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled. Vanilla 2.0.17.9+ Fix from $1,9502020-01-22 MEDIUM 5.4 CVE-2019-8279 Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum. Vanilla Forums 2.5.0+ Fix from $1,6002019-03-02 HIGH 7.2 CVE-2018-19499 Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in… Vanilla 2.5.5 / 2.6.2+ Fix from $1,9502018-11-23 CRITICAL 9.8 CVE-2018-18903EPSS 5% Vanilla 2.6.x before 2.6.4 allows remote code execution. Vanilla 2.6.4+ Fix from $2,3002018-11-03 MEDIUM 6.1 CVE-2018-17571 Vanilla before 2.6.1 allows XSS via the email field of a profile. Vanilla 2.6.1+ Fix from $1,6002018-09-28 MEDIUM 6.5 CVE-2018-16410 Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invi… Vanilla Patch available Fix from $1,6002018-09-03 HIGH 8.0 CVE-2017-1000432 Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access Vanilla Forums 2.1.5+ Fix from $1,9502018-01-02 HIGH 7.5 CVE-2016-10073EPSS 84% The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and… Vanilla after 2.3.0 Fix from $1,9502017-05-23 HIGH 7.5 CVE-2013-3527 Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter n… Vanilla after 2.0.18.7 Fix from $1,9502013-05-10 HIGH 7.5 CVE-2013-3528EPSS 6% Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object … Vanilla after 2.0.18.7 Fix from $1,9502013-05-10 MEDIUM 5.0 CVE-2011-3812 Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an… Vanilla Mitigation only Fix from $1,6002011-09-24 MEDIUM 6.4 CVE-2011-0910 The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain ac… Vanilla after 2.0.17.5 Fix from $1,6002011-02-08 MEDIUM 5.8 CVE-2011-0908 Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing a… Vanilla after 2.0.17.5 Fix from $1,6002011-02-08