Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vanillaforums vanilla 2.0.11 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2011-0526
Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums prior to 2.0.17 allows remote malicious users to inject arbitrary web script or HTML via the Target parameter in a /entry/signin action.
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla
NA
CVE-2011-0908
Open redirect vulnerability in Vanilla Forums prior to 2.0.17.6 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla
NA
CVE-2011-0910
The cookie implementation in Vanilla Forums prior to 2.0.17.6 makes it easier for remote malicious users to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks.
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla
NA
CVE-2011-0909
Cross-site scripting (XSS) vulnerability in Vanilla Forums prior to 2.0.17.6 allows remote malicious users to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla
NA
CVE-2012-4954
The edit-profile page in Vanilla Forums prior to 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.
Vanillaforums Vanilla Forums
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.0
Vanillaforums Vanilla 2.0.1
Vanillaforums Vanilla 2.0.2
Vanillaforums Vanilla 2.0.3
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla 2.0.7
Vanillaforums Vanilla 2.0.8
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.16.1
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.17.2
NA
CVE-2013-3527
Multiple SQL injection vulnerabilities in Vanilla Forums prior to 2.0.18.8 allow remote malicious users to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest.
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.1
Vanillaforums Vanilla 2.0.2
Vanillaforums Vanilla 2.0.3
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla 2.0.7
Vanillaforums Vanilla 2.0.8
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.16.1
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.4
1 EDB exploit
NA
CVE-2013-3528
Unspecified vulnerability in the update check in Vanilla Forums prior to 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection."
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.1
Vanillaforums Vanilla 2.0.2
Vanillaforums Vanilla 2.0.3
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla 2.0.7
Vanillaforums Vanilla 2.0.8
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.16.1
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.4
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started