Known Vulnerabilities for products from Vanillaforums

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Vanillaforums".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2020-8825 json index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. 5.4 - MEDIUM 2020-02-10 2021-12-30
CVE-2019-9889 json In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a r... 2.7 - LOW 2019-03-21 2019-03-26
CVE-2019-8279 json Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message ... 5.4 - MEDIUM 2019-03-02 2019-03-04
CVE-2018-19499 json Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachabl... 7.2 - HIGH 2018-11-23 2019-10-03
CVE-2018-18903 json Vanilla 2.6.x before 2.6.4 allows remote code execution. 9.8 - CRITICAL 2018-11-03 2018-12-26
CVE-2018-17571 json Vanilla before 2.6.1 allows XSS via the email field of a profile. 6.1 - MEDIUM 2018-09-28 2018-11-15
CVE-2018-16410 json Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/das... 6.5 - MEDIUM 2018-09-03 2018-10-25
CVE-2018-15833 json In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to... 4.3 - MEDIUM 2018-08-26 2020-08-24
CVE-2017-1000432 json Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access 8 - HIGH 2018-01-02 2018-01-17
CVE-2016-10073 json The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email dom... Not Provided 2017-05-23 2025-04-20
CVE-2014-9685 json Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote at... Not Provided 2015-02-25 2026-05-06
CVE-2013-3528 json Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vect... Not Provided 2013-05-10 2026-04-29
CVE-2013-3527 json Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL comm... Not Provided 2013-05-10 2026-04-29
CVE-2012-6557 json Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to ... Not Provided 2013-05-23 2026-04-29
CVE-2012-6555 json Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject... Not Provided 2013-05-23 2026-04-29
CVE-2012-4954 json The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings ... Not Provided 2012-11-15 2026-04-29
CVE-2011-3812 json Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the... Not Provided 2011-09-24 2026-04-29
CVE-2011-3614 json An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9. 9.8 - CRITICAL 2020-01-22 2020-01-28
CVE-2011-3613 json An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled. 7.5 - HIGH 2020-01-22 2020-01-28
CVE-2011-1009 json Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter. 6.1 - MEDIUM 2020-02-05 2020-06-04

Known software with vulnerabilities from Vanillaforums

Type Vendor Product Version
ApplicationVanillaforumsVanilla-
ApplicationVanillaforumsVanilla Forums-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report