Invision Power Board
by Board Power
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-3725 | Cri | 0.64 | 9.8 | 0.02 | Feb 12, 2020 | Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution. | ||
| CVE-2009-5159 | Med | 0.40 | 6.1 | 0.03 | Mar 13, 2020 | Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment. | ||
| CVE-2019-8278 | Med | 0.40 | 6.1 | 0.02 | Mar 2, 2019 | Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution. | ||
| CVE-2007-4912 | 0.00 | — | 0.01 | Sep 17, 2007 | Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML into user profile fields via unspecified vectors related to character sets other… | |||
| CVE-2007-4914 | 0.00 | — | 0.01 | Sep 17, 2007 | Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment form, related to (1)… |
- risk 0.64cvss 9.8epss 0.02
Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
- risk 0.40cvss 6.1epss 0.03
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
- risk 0.40cvss 6.1epss 0.02
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
- CVE-2007-4912Sep 17, 2007risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML into user profile fields via unspecified vectors related to character sets other…
- CVE-2007-4914Sep 17, 2007risk 0.00cvss —epss 0.01
Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment form, related to (1)…