VYPR

Invisioncommunity

by Invision Power Services

CVEs (2)

  • CVE-2025-47916CriMay 16, 2025
    risk 0.74cvss 10.0epss 0.85

    Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be…

  • CVE-2024-30163CriJun 7, 2024
    risk 0.64cvss 9.8epss 0.09

    Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to…