Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2010-4266

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
Attacker Value
Unknown

CVE-2010-4264

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.
Attacker Value
Unknown

CVE-2019-8279

Disclosure Date: March 02, 2019 (last updated November 27, 2024)
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.
0
Attacker Value
Unknown

CVE-2018-15833

Disclosure Date: August 26, 2018 (last updated November 27, 2024)
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items).
0
Attacker Value
Unknown

CVE-2017-1000432

Disclosure Date: January 02, 2018 (last updated November 26, 2024)
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
0
Attacker Value
Unknown

CVE-2014-9685

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-4954

Disclosure Date: November 15, 2012 (last updated October 05, 2023)
The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.
0