Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2010-4264
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the cli…
Vanilla Forums
2.0.10+
MEDIUM 6.1
CVE-2010-4266
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
Vanilla Forums
2.0.10+
MEDIUM 5.4
CVE-2020-8825
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
Vanilla
No fix yet
MEDIUM 6.1
CVE-2011-1009
Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.
Vanilla
after 2.0.17.5
CRITICAL 9.8
CVE-2011-3614
An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.
Vanilla
2.0.17.9+
HIGH 7.5
CVE-2011-3613
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
Vanilla
2.0.17.9+
MEDIUM 5.4
CVE-2019-8279
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.
Vanilla Forums
2.5.0+
HIGH 7.2
CVE-2018-19499
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in…
Vanilla
2.5.5 / 2.6.2+
CRITICAL 9.8
CVE-2018-18903EPSS 5%
Vanilla 2.6.x before 2.6.4 allows remote code execution.
Vanilla
2.6.4+
MEDIUM 6.1
CVE-2018-17571
Vanilla before 2.6.1 allows XSS via the email field of a profile.
Vanilla
2.6.1+
MEDIUM 6.5
CVE-2018-16410
Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invi…
Vanilla
Patch available
HIGH 8.0
CVE-2017-1000432
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
Vanilla Forums
2.1.5+
HIGH 7.5
CVE-2016-10073EPSS 84%
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and…
Vanilla
after 2.3.0
HIGH 7.5
CVE-2013-3527
Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter n…
Vanilla
after 2.0.18.7
HIGH 7.5
CVE-2013-3528EPSS 6%
Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object …
Vanilla
after 2.0.18.7
MEDIUM 5.0
CVE-2011-3812
Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an…
Vanilla
Mitigation only
MEDIUM 6.4
CVE-2011-0910
The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain ac…
Vanilla
after 2.0.17.5
MEDIUM 5.8
CVE-2011-0908
Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing a…
Vanilla
after 2.0.17.5