Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vanilla forums vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2014-9685
Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums prior to 2.0.18.13 and 2.1.x prior to 2.1.1 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Vanillaforums Vanilla
Vanillaforums Vanilla Forums 2.1
516
VMScore
CVE-2010-4266
It was found in vanilla forums prior to 2.0.10 a potential linkbait vulnerability in dispatcher.
Vanillaforums Vanilla Forums
605
VMScore
CVE-2017-1000432
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
Vanillaforums Vanilla Forums
1 EDB exploit
312
VMScore
CVE-2019-8279
Multiple stored XSS in Vanilla Forums prior to 2.5 allow remote malicious users to inject arbitrary JavaScript code into any message on forum.
Vanillaforums Vanilla Forums
356
VMScore
CVE-2018-15833
In Vanilla prior to 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items).
Vanillaforums Vanilla Forums
383
VMScore
CVE-2010-4264
It was found in vanilla forums prior to 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.
Vanillaforums Vanilla Forums
755
VMScore
CVE-2013-3528
Unspecified vulnerability in the update check in Vanilla Forums prior to 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection."
Vanillaforums Vanilla 2.0.18.4
Vanillaforums Vanilla 2.0.18.3
Vanillaforums Vanilla 2.0.18
Vanillaforums Vanilla 2.0.17.10
Vanillaforums Vanilla 2.0.17.8
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.18.6
Vanillaforums Vanilla 2.0.18.5
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.16.1
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.7
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.7
Vanillaforums Vanilla 2.0.16
1 EDB exploit
516
VMScore
CVE-2011-0908
Open redirect vulnerability in Vanilla Forums prior to 2.0.17.6 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.17.1
755
VMScore
CVE-2013-3527
Multiple SQL injection vulnerabilities in Vanilla Forums prior to 2.0.18.8 allow remote malicious users to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest.
Vanillaforums Vanilla 2.0.18.3
Vanillaforums Vanilla 2.0.18.1
Vanillaforums Vanilla 2.0.18
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla 2.0.17.8
Vanillaforums Vanilla 2.0.17.9
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.3
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.18.6
Vanillaforums Vanilla 2.0.18.5
Vanillaforums Vanilla 2.0.18.4
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.17.10
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.17.3
1 EDB exploit
312
VMScore
CVE-2012-4954
The edit-profile page in Vanilla Forums prior to 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.18
Vanillaforums Vanilla 2.0.18.1
Vanillaforums Vanilla 2.0.17.10
Vanillaforums Vanilla 2.0.7
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla 2.0.17.5
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.17.9
Vanillaforums Vanilla 2.0.17.8
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.18.3
Vanillaforums Vanilla 2.0.16.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »