Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Invisioncommunity CRITICAL 9.8
CVE-2025-47916EPSS 84%

Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeed…

Fix: 5.0.7+
Fix from $2,300 2025-05-16
Invisioncommunity CRITICAL 9.8
CVE-2024-30163EPSS 9%

Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_…

Fix: 4.7.16+
Fix from $2,300 2024-06-07
Ips Community Suite CRITICAL 9.1
CVE-2021-40604

A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or…

Fix: 4.6.2+
Fix from $2,300 2022-06-13
Invision Power Board MEDIUM 6.1
CVE-2021-39249

Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictab…

Fix: 4.6.5.1+
Fix from $1,600 2021-08-17
Invision Power Board MEDIUM 5.4
CVE-2021-39250

Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file ca…

Fix: 4.6.5.1+
Fix from $1,600 2021-08-17
Ips Community Suite HIGH 8.8
CVE-2021-32924EPSS 20%

Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages…

Fix: 4.6.0+
Fix from $1,950 2021-06-01
Ips Community Suite HIGH 8.8
CVE-2021-3025

Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular acti…

Fix: 4.5.4.2+
Fix from $1,950 2021-01-08
Ips Community Suite MEDIUM 6.1
CVE-2021-3026

Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment.

Fix: 4.5.4.2+
Fix from $1,600 2021-01-05
Invision Power Board MEDIUM 6.1
CVE-2009-5159

Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.

Fix: after 3.0.4
Fix from $1,600 2020-03-13
Invision Power Board CRITICAL 9.8
CVE-2013-3725

Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.

Fix: 4.0.0+
Fix from $2,300 2020-02-12
Invision Power Board CRITICAL 9.8
CVE-2012-2226EPSS 7%

Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute…

Fix: 3.3.1+
Fix from $2,300 2020-01-09
Invision Power Board MEDIUM 6.1
CVE-2019-8278

Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.

Fix: after 3.4.8
Fix from $1,600 2019-03-02
Invision Power Board HIGH 8.8
CVE-2014-4928

SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via …

Fix: 3.4.6+
Fix from $1,950 2018-03-20
Invision Power Board CRITICAL 9.8
CVE-2017-8898

Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invisio…

Fix: after 4.1.19.2
Fix from $2,300 2017-05-11
Invision Power Board HIGH 8.1
CVE-2017-8899

Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments…

Fix: after 4.1.19.2
Fix from $1,950 2017-05-11
Invision Power Board MEDIUM 6.1
CVE-2017-8897

Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/in…

Fix: after 4.1.19.2
Fix from $1,600 2017-05-11
Invision Power Board MEDIUM 5.9
CVE-2016-2564

Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy…

Fix: after 4.1.8.1
Fix from $1,600 2017-04-23
Invision Power Board HIGH 7.8
CVE-2015-6812

Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial…

Fix: after 4.0.11
Fix from $1,950 2015-09-04
Invision Power Board HIGH 7.5
CVE-2014-9239

SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and …

Patch available
Fix from $1,950 2014-12-03
Invision Power Board HIGH 10.0
CVE-2012-5692EPSS 26%

Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and rem…

Patch available
Fix from $1,950 2012-10-31
Invision Power Board HIGH 7.5
CVE-2009-3974

Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute arbitrary …

Patch available
Fix from $1,950 2009-11-18