VYPR

Vanilla Forums

Sign in to watch

by Lussumo

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2014-96850.000.00Feb 25, 2015Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2012-49540.000.01Nov 15, 2012The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.