Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vanilla vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2018-16410
Vanilla prior to 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php.
Vanillaforums Vanilla 2.6.1
3.5
CVSSv2
CVE-2020-8825
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
Vanillaforums Vanilla 2.6.3
1 Github repository
5
CVSSv2
CVE-2011-3812
Vanilla 2.0.16 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Minify/min/utils.php and certain other files.
Vanillaforums Vanilla 2.0.16
4.3
CVSSv2
CVE-2006-0541
Multiple cross-site scripting (XSS) vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote malicious users to inject arbitrary web script or HTML via unknown vectors related to "posting new messages."
Tachyon Vanilla Guestbook 1.0 Beta
7.5
CVSSv2
CVE-2006-0540
Multiple SQL injection vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Tachyon Vanilla Guestbook 1.0 Beta
9.3
CVSSv2
CVE-2007-1251
Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote malicious users to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handlin...
Netrek Netrek Vanilla Server 2.12.0
1 EDB exploit
4.3
CVSSv2
CVE-2012-6556
Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote malicious users to inject arbitrary web script or HTML via the (1) User/FirstName or (2) User/LastName parameter to the edit user page. NOTE: some of these detai...
Jspautsch Firstlastnames 1.1.1
1 EDB exploit
4.3
CVSSv2
CVE-2012-6557
Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote malicious users to inject arbitrary web script or HTML via the (1) AboutMe/RealName, (2) AboutMe/Name, (3) AboutMe/Quote, (4) AboutMe/Loc, (5) AboutMe/Emp, (6) AboutMe/...
Zodiacdm Aboutme-plugin 1.1.1
1 EDB exploit
NA
CVE-2013-2749
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3528. Reason: This candidate is a reservation duplicate of CVE-2013-3528. Notes: All CVE users should reference CVE-2013-3528 instead of this candidate. All references and descriptions in this candidate have ...
1 EDB exploit
4.3
CVSSv2
CVE-2012-6555
Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote malicious users to inject arbitrary web script or HTML via the discussion title.
Vanillaforums Latestcomment 1.1
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »