Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vanilla vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2008-3759
Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and previous versions has unknown impact and remote attack vectors.
Lussumo Vanilla 1.0.3
Lussumo Vanilla 1.1
Lussumo Vanilla 1.0.1
Lussumo Vanilla 1.0.2
Lussumo Vanilla 0.9.2
Lussumo Vanilla 1
Lussumo Vanilla 1.1.3
Lussumo Vanilla
Lussumo Vanilla 1.1.1
Lussumo Vanilla 1.1.2
383
VMScore
CVE-2011-0526
Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums prior to 2.0.17 allows remote malicious users to inject arbitrary web script or HTML via the Target parameter in a /entry/signin action.
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.11
383
VMScore
CVE-2014-9685
Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums prior to 2.0.18.13 and 2.1.x prior to 2.1.1 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Vanillaforums Vanilla
Vanillaforums Vanilla Forums 2.1
435
VMScore
CVE-2009-1845
Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote malicious users to inject arbitrary web script or HTML via the RequestName parameter.
Lussumo Vanilla 1.1.5
Lussumo Vanilla 1.1.7
1 EDB exploit
383
VMScore
CVE-2018-17571
Vanilla prior to 2.6.1 allows XSS via the email field of a profile.
Vanillaforums Vanilla
445
VMScore
CVE-2011-3613
An issue exists in Vanilla Forums prior to 2.0.17.9 due to the way cookies are handled.
Vanillaforums Vanilla
668
VMScore
CVE-2011-3614
An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums prior to 2.0.17.9.
Vanillaforums Vanilla
505
VMScore
CVE-2016-10073
The from method in library/core/class.email.php in Vanilla Forums prior to 2.3.1 allows remote malicious users to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.
Vanillaforums Vanilla
1 EDB exploit
1 Article
383
VMScore
CVE-2011-1009
Vanilla Forums 2.0.17.1 up to and including 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.
Vanillaforums Vanilla
515
VMScore
CVE-2006-3850
PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and previous versions, when /conf/old_settings.php exists, allows remote malicious users to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a th...
Lussumo Vanilla
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »