VYPR
Vendor

Lussumo

Products
2
CVEs
34
Across products
34
Status
Private

Products

2

Recent CVEs

34
View all 34 CVEs →
  • CVE-2011-3614CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.02

    An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.

  • CVE-2018-18903CriNov 3, 2018
    risk 0.64cvss 9.8epss 0.05

    Vanilla 2.6.x before 2.6.4 allows remote code execution.

  • CVE-2016-10073HigMay 23, 2017
    risk 0.58cvss 7.5epss 0.84

    The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.

  • CVE-2017-1000432HigJan 2, 2018
    risk 0.55cvss 8.0epss 0.02

    Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access

  • CVE-2011-3613HigJan 22, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.

  • CVE-2018-19499HigNov 23, 2018
    risk 0.47cvss 7.2epss 0.02

    Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.

  • CVE-2018-16410MedSep 3, 2018
    risk 0.42cvss 6.5epss 0.01

    Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php.

  • CVE-2010-4266MedJun 22, 2021
    risk 0.40cvss 6.1epss 0.01

    It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.

  • CVE-2018-17571MedSep 28, 2018
    risk 0.40cvss 6.1epss 0.01

    Vanilla before 2.6.1 allows XSS via the email field of a profile.

  • CVE-2020-8825MedFeb 10, 2020
    risk 0.38cvss 5.4epss 0.02

    index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.

  • CVE-2019-8279MedMar 2, 2019
    risk 0.35cvss 5.4epss 0.01

    Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.

  • CVE-2010-4264MedJun 22, 2021
    risk 0.33cvss 6.1epss 0.01

    It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.

  • CVE-2011-1009MedFeb 5, 2020
    risk 0.33cvss 6.1epss 0.01

    Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.

  • CVE-2018-15833MedAug 26, 2018
    risk 0.28cvss 4.3epss 0.01

    In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items).

  • CVE-2012-6555May 23, 2013
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title.

  • CVE-2010-1337Apr 9, 2010
    risk 0.03cvss epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE'] parameters.

  • CVE-2009-1845Jun 1, 2009
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the RequestName parameter.

  • CVE-2008-3758Aug 21, 2008
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Lussumo Vanilla 1.1.4 and earlier (1) allow remote attackers to inject arbitrary web script or HTML via the NewPassword parameter to people.php, and allow remote authenticated users to inject arbitrary web script or HTML via…

  • CVE-2007-5644Oct 23, 2007
    risk 0.03cvss epss 0.02

    Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthorized sort operations and other activities.

  • CVE-2007-5643Oct 23, 2007
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Lussumo Vanilla 1.1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the CategoryID parameter to ajax/sortcategories.php or (2) an unspecified vector to ajax/sortroles.php.