Vulnerabilities (CVE)

Filtered by vendor Vanillaforums Subscribe
Total 26 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-0910 1 Vanillaforums 1 Vanilla 2024-11-21 6.4 MEDIUM N/A
The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks.
CVE-2011-0909 1 Vanillaforums 1 Vanilla 2024-11-21 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
CVE-2011-0908 1 Vanillaforums 1 Vanilla 2024-11-21 5.8 MEDIUM N/A
Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
CVE-2011-0526 1 Vanillaforums 1 Vanilla 2024-11-21 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web script or HTML via the Target parameter in a /entry/signin action.
CVE-2010-4266 1 Vanillaforums 1 Vanilla Forums 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
CVE-2010-4264 1 Vanillaforums 1 Vanilla Forums 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.