Known Vulnerabilities for products from Vanillaforums
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Vanillaforums".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-8825 json | index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. | 5.4 - MEDIUM | 2020-02-10 | 2021-12-30 |
| CVE-2019-9889 json | In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a r... | 2.7 - LOW | 2019-03-21 | 2019-03-26 |
| CVE-2019-8279 json | Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message ... | 5.4 - MEDIUM | 2019-03-02 | 2019-03-04 |
| CVE-2018-19499 json | Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachabl... | 7.2 - HIGH | 2018-11-23 | 2019-10-03 |
| CVE-2018-18903 json | Vanilla 2.6.x before 2.6.4 allows remote code execution. | 9.8 - CRITICAL | 2018-11-03 | 2018-12-26 |
| CVE-2018-17571 json | Vanilla before 2.6.1 allows XSS via the email field of a profile. | 6.1 - MEDIUM | 2018-09-28 | 2018-11-15 |
| CVE-2018-16410 json | Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/das... | 6.5 - MEDIUM | 2018-09-03 | 2018-10-25 |
| CVE-2018-15833 json | In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to... | 4.3 - MEDIUM | 2018-08-26 | 2020-08-24 |
| CVE-2017-1000432 json | Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access | 8 - HIGH | 2018-01-02 | 2018-01-17 |
| CVE-2016-10073 json | The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email dom... | Not Provided | 2017-05-23 | 2025-04-20 |
| CVE-2014-9685 json | Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote at... | Not Provided | 2015-02-25 | 2026-05-06 |
| CVE-2013-3528 json | Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vect... | Not Provided | 2013-05-10 | 2026-04-29 |
| CVE-2013-3527 json | Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL comm... | Not Provided | 2013-05-10 | 2026-04-29 |
| CVE-2012-6557 json | Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to ... | Not Provided | 2013-05-23 | 2026-04-29 |
| CVE-2012-6555 json | Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject... | Not Provided | 2013-05-23 | 2026-04-29 |
| CVE-2012-4954 json | The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings ... | Not Provided | 2012-11-15 | 2026-04-29 |
| CVE-2011-3812 json | Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the... | Not Provided | 2011-09-24 | 2026-04-29 |
| CVE-2011-3614 json | An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9. | 9.8 - CRITICAL | 2020-01-22 | 2020-01-28 |
| CVE-2011-3613 json | An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled. | 7.5 - HIGH | 2020-01-22 | 2020-01-28 |
| CVE-2011-1009 json | Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter. | 6.1 - MEDIUM | 2020-02-05 | 2020-06-04 |
Known software with vulnerabilities from Vanillaforums
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Vanillaforums | Vanilla | - |
| Application | Vanillaforums | Vanilla Forums | - |