Unrated severityNVD Advisory· Published Feb 8, 2011· Updated Jun 16, 2026
CVE-2011-0909
CVE-2011-0909
Description
Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
Affected products
15cpe:2.3:a:vanillaforums:vanilla:*:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:vanillaforums:vanilla:*:*:*:*:*:*:*:*range: <=2.0.17.5
- cpe:2.3:a:vanillaforums:vanilla:2.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.17:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.17.1:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.17.2:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.17.3:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.17.4:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.9:*:*:*:*:*:*:*
- Range: <2.0.17.6
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.