Vulnerabilities > Invisioncommunity > Invision Power Board > Low

DATE CVE VULNERABILITY TITLE RISK
2021-08-17 CVE-2021-39250 Cross-site Scripting vulnerability in Invisioncommunity Invision Power Board
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content.
3.5