Vulnerabilities > Vanillaforums > Vanilla > 2.5.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-03-21 | CVE-2019-9889 | Path Traversal vulnerability in Vanillaforums Vanilla In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. | 2.7 |
2018-09-28 | CVE-2018-17571 | Cross-site Scripting vulnerability in Vanillaforums Vanilla Vanilla before 2.6.1 allows XSS via the email field of a profile. | 6.1 |