Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
invisioncommunity vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2021-3025
Invision Community IPS Community Suite prior to 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php).
Invisioncommunity Ips Community Suite
9.1
CVSSv3
CVE-2021-40604
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite prior to 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by ...
Invisioncommunity Ips Community Suite
6.1
CVSSv3
CVE-2021-39249
Invision Community (aka IPS Community Suite or IP-Board) prior to 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.
Invisioncommunity Invision Power Board
8.8
CVSSv3
CVE-2014-4928
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) prior to 3.4.6 allows remote malicious users to execute arbitrary SQL commands via the cId parameter.
Invisioncommunity Invision Power Board
5.4
CVSSv3
CVE-2021-39250
Invision Community (aka IPS Community Suite or IP-Board) prior to 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an ad...
Invisioncommunity Invision Power Board
6.1
CVSSv3
CVE-2021-3026
Invision Community IPS Community Suite prior to 4.5.4.2 allows XSS during the quoting of a post or comment.
Invisioncommunity Ips Community Suite
6.1
CVSSv3
CVE-2017-8897
Invision Power Services (IPS) Community Suite 4.1.19.2 and previous versions has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a malicious announ...
Invisioncommunity Invision Power Board
9.8
CVSSv3
CVE-2013-3725
Invision Power Board (IPB) up to and including 3.x allows admin account takeover leading to code execution.
Invisioncommunity Invision Power Board
NA
CVE-2015-6812
Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) prior to 4.0.12.1 allows remote malicious users to cause a denial of service (loop and memory consumption) via a crafted URL.
Invisioncommunity Invision Power Board
8.8
CVSSv3
CVE-2021-32924
Invision Community (aka IPS Community Suite) prior to 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method.
Invisioncommunity Ips Community Suite
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »