Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
invisioncommunity invision power board vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2013-3725
Invision Power Board (IPB) up to and including 3.x allows admin account takeover leading to code execution.
Invisioncommunity Invision Power Board
9.8
CVSSv3
CVE-2012-2226
Invision Power Board prior to 3.3.1 fails to sanitize user-supplied input which could allow remote malicious users to obtain sensitive information or execute arbitrary code by uploading a malicious file.
Invisioncommunity Invision Power Board
1 EDB exploit
9.8
CVSSv3
CVE-2017-8898
Invision Power Services (IPS) Community Suite 4.1.19.2 and previous versions has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&...
Invisioncommunity Invision Power Board
8.8
CVSSv3
CVE-2014-4928
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) prior to 3.4.6 allows remote malicious users to execute arbitrary SQL commands via the cId parameter.
Invisioncommunity Invision Power Board
8.1
CVSSv3
CVE-2017-8899
Invision Power Services (IPS) Community Suite 4.1.19.2 and previous versions has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power Board user and can be used to gain access to moder...
Invisioncommunity Invision Power Board
8.1
CVSSv3
CVE-2016-6174
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) prior to 4.1.13, when used with PHP prior to 5.4.24 or 5.5.x prior to 5.5.8, allows remote malicious users to execute arbitrary code v...
Invisioncommunity Invision Power Board
Php Php 5.5.2
Php Php 5.5.1
Php Php 5.5.0
Php Php 5.5.7
Php Php 5.5.6
Php Php 5.5.5
Php Php 5.5.4
Php Php 5.5.3
Php Php
1 EDB exploit
6.1
CVSSv3
CVE-2021-39249
Invision Community (aka IPS Community Suite or IP-Board) prior to 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.
Invisioncommunity Invision Power Board
6.1
CVSSv3
CVE-2009-5159
Invision Power Board (aka IPB or IP.Board) 2.x up to and including 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
Invisioncommunity Invision Power Board
Microsoft Internet Explorer 5
6.1
CVSSv3
CVE-2019-8278
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
Invisioncommunity Invision Power Board
6.1
CVSSv3
CVE-2017-8897
Invision Power Services (IPS) Community Suite 4.1.19.2 and previous versions has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a malicious announ...
Invisioncommunity Invision Power Board
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
firmware
CVE-2023-52866
CVE-2024-4367
CVE-2024-1721
CVE-2023-34992
XML injection
CVE-2023-52817
SQL
CVE-2023-52855
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »