Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown

CVE-2010-4266

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
Attacker Value
Unknown

CVE-2010-4264

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.
Attacker Value
Unknown

CVE-2020-8825

Disclosure Date: February 10, 2020 (last updated February 21, 2025)
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
Attacker Value
Unknown

CVE-2011-1009

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.
Attacker Value
Unknown

CVE-2011-3614

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.
Attacker Value
Unknown

CVE-2011-3613

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
Attacker Value
Unknown

CVE-2019-9889

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code under the context of the web server.
0
Attacker Value
Unknown

CVE-2019-8279

Disclosure Date: March 02, 2019 (last updated November 27, 2024)
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.
0
Attacker Value
Unknown

CVE-2018-19499

Disclosure Date: November 23, 2018 (last updated November 27, 2024)
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.
0
Attacker Value
Unknown

CVE-2018-18903

Disclosure Date: November 03, 2018 (last updated November 27, 2024)
Vanilla 2.6.x before 2.6.4 allows remote code execution.
0