VYPR
Medium severity6.1OSV Advisory· Published Sep 28, 2018· Updated Jun 17, 2026

CVE-2018-17571

CVE-2018-17571

Description

Vanilla before 2.6.1 allows XSS via the email field of a profile.

Affected products

3
  • Vanilla OS/VanillaOSV2 versions
    list+ 1 more
    • (no CPE)range: list
    • (no CPE)range: <2.6.1
  • cpe:2.3:a:vanillaforums:vanilla:*:*:*:*:*:*:*:*
    Range: <2.6.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.