Releases11
Frequency1 month 1 week
Last Release
Stars114
Straightforward concurrency for Python

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 2.6.35.4 MEDIUM3.5 LOW

index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.

>= 2.0.17.1, <= 2.0.17.56.1 MEDIUM4.3 MEDIUM

Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.

< 2.0.17.97.5 HIGH5 MEDIUM

An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.

< 2.0.17.99.8 CRITICAL7.5 HIGH

An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.

< 2.6.44 MEDIUM

In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code under the context of the web server.

>= 2.6.0, < 2.6.2, < 2.5.56.5 MEDIUM

Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.

>= 2.6.0, < 2.6.47.5 HIGH

Vanilla 2.6.x before 2.6.4 allows remote code execution.

< 2.6.14.3 MEDIUM

Vanilla before 2.6.1 allows XSS via the email field of a profile.

= 2.6.14 MEDIUM

Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php.

<= 2.3.05 MEDIUM

The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.

<= 2.0.18.124.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.