Known Vulnerabilities for products from Invisioncommunity
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Invisioncommunity".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-40604 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.1 - CRITICAL | 2022-06-13 | 2022-06-27 |
| CVE-2021-39250 json | Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, bec... | 5.4 - MEDIUM | 2021-08-17 | 2021-08-25 |
| CVE-2021-39249 json | Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploade... | 6.1 - MEDIUM | 2021-08-17 | 2022-07-12 |
| CVE-2021-32924 json | Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS... | 8.8 - HIGH | 2021-06-01 | 2021-06-16 |
| CVE-2021-3026 json | Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment. | 6.1 - MEDIUM | 2021-01-05 | 2021-01-06 |
| CVE-2021-3025 json | Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter ... | 8.8 - HIGH | 2021-01-08 | 2021-01-15 |
| CVE-2020-29477 json | Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an a... | 4.8 - MEDIUM | 2020-12-30 | 2021-01-04 |
| CVE-2019-8278 json | Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution. | 6.1 - MEDIUM | 2019-03-02 | 2019-03-07 |
| CVE-2017-8899 json | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure i... | 8.1 - HIGH | 2017-05-11 | 2020-06-03 |
| CVE-2017-8898 json | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege es... | 9.8 - CRITICAL | 2017-05-11 | 2020-06-03 |
| CVE-2017-8897 json | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.... | 6.1 - MEDIUM | 2017-05-11 | 2020-06-03 |
| CVE-2016-6174 json | applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, ... | 8.1 - HIGH | 2016-07-12 | 2020-06-03 |
| CVE-2016-2564 json | Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function ... | 5.9 - MEDIUM | 2017-04-23 | 2023-11-07 |
| CVE-2015-6812 json | Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote att... | 7.8 - HIGH | 2015-09-04 | 2020-06-03 |
| CVE-2014-9239 json | SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB... | 7.5 - HIGH | 2014-12-03 | 2020-06-03 |
| CVE-2014-5106 json | Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows remot... | 4.3 - MEDIUM | 2014-07-28 | 2020-06-03 |
| CVE-2014-4928 json | SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arb... | 8.8 - HIGH | 2018-03-20 | 2020-06-03 |
| CVE-2014-3149 json | Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, a... | 4.3 - MEDIUM | 2014-07-03 | 2020-06-03 |
| CVE-2013-3725 json | Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution. | 9.8 - CRITICAL | 2020-02-12 | 2020-02-25 |
| CVE-2012-5692 json | Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x ha... | Not Provided | 2012-10-31 | 2026-04-29 |
Known software with vulnerabilities from Invisioncommunity
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Invisioncommunity | Community | 4.5.4 |
| Application | Invisioncommunity | Invision Power Board | 2.0 |
| Application | Invisioncommunity | Ips Community Suite | 4.5.2 |