Vulnerabilities > Vanillaforums > High

DATE CVE VULNERABILITY TITLE RISK
2020-01-22 CVE-2011-3613 Information Exposure vulnerability in Vanillaforums Vanilla
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
network
low complexity
vanillaforums CWE-200
7.5
2018-11-23 CVE-2018-19499 Deserialization of Untrusted Data vulnerability in Vanillaforums Vanilla
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.
network
low complexity
vanillaforums CWE-502
7.2
2018-01-02 CVE-2017-1000432 Cross-Site Request Forgery (CSRF) vulnerability in Vanillaforums Vanilla Forums
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
network
low complexity
vanillaforums CWE-352
8.0
2017-05-23 CVE-2016-10073 Information Exposure vulnerability in Vanillaforums Vanilla
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.
network
low complexity
vanillaforums CWE-200
7.5