Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vanilla vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-2749
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3528. Reason: This candidate is a reservation duplicate of CVE-2013-3528. Notes: All CVE users should reference CVE-2013-3528 instead of this candidate. All references and descriptions in this candidate have ...
1 EDB exploit
4.3
CVSSv2
CVE-2012-6555
Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote malicious users to inject arbitrary web script or HTML via the discussion title.
Vanillaforums Latestcomment 1.1
1 EDB exploit
4.3
CVSSv2
CVE-2012-6556
Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote malicious users to inject arbitrary web script or HTML via the (1) User/FirstName or (2) User/LastName parameter to the edit user page. NOTE: some of these detai...
Jspautsch Firstlastnames 1.1.1
1 EDB exploit
4.3
CVSSv2
CVE-2012-6557
Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote malicious users to inject arbitrary web script or HTML via the (1) AboutMe/RealName, (2) AboutMe/Name, (3) AboutMe/Quote, (4) AboutMe/Loc, (5) AboutMe/Emp, (6) AboutMe/...
Zodiacdm Aboutme-plugin 1.1.1
1 EDB exploit
7.5
CVSSv2
CVE-2013-3527
Multiple SQL injection vulnerabilities in Vanilla Forums prior to 2.0.18.8 allow remote malicious users to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest.
Vanillaforums Vanilla 2.0.18.3
Vanillaforums Vanilla 2.0.18.1
Vanillaforums Vanilla 2.0.18
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla 2.0.17.8
Vanillaforums Vanilla 2.0.17.9
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.3
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.18.6
Vanillaforums Vanilla 2.0.18.5
Vanillaforums Vanilla 2.0.18.4
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.17.10
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.17.3
1 EDB exploit
7.5
CVSSv2
CVE-2013-3528
Unspecified vulnerability in the update check in Vanilla Forums prior to 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection."
Vanillaforums Vanilla 2.0.18.4
Vanillaforums Vanilla 2.0.18.3
Vanillaforums Vanilla 2.0.18
Vanillaforums Vanilla 2.0.17.10
Vanillaforums Vanilla 2.0.17.8
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.18.6
Vanillaforums Vanilla 2.0.18.5
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.16.1
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.7
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.7
Vanillaforums Vanilla 2.0.16
1 EDB exploit
3.5
CVSSv2
CVE-2012-4954
The edit-profile page in Vanilla Forums prior to 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.18
Vanillaforums Vanilla 2.0.18.1
Vanillaforums Vanilla 2.0.17.10
Vanillaforums Vanilla 2.0.7
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla 2.0.17.5
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.17.9
Vanillaforums Vanilla 2.0.17.8
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.18.3
Vanillaforums Vanilla 2.0.16.1
5
CVSSv2
CVE-2011-3812
Vanilla 2.0.16 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Minify/min/utils.php and certain other files.
Vanillaforums Vanilla 2.0.16
4.3
CVSSv2
CVE-2011-0909
Cross-site scripting (XSS) vulnerability in Vanilla Forums prior to 2.0.17.6 allows remote malicious users to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.17
5.8
CVSSv2
CVE-2011-0908
Open redirect vulnerability in Vanilla Forums prior to 2.0.17.6 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.17.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
XXE
CVE-2024-34490
SQL injection
CVE-2024-34488
CVE-2024-4507
CVE-2023-7028
CVE-2024-23187
TCP
CVE-2024-4439
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »