Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Invision Power Services

First CVE: Oct 11, 2002Active for: 24 yearsTotal CVEs: 73
41.9
VTI Score
High

Invision Power Services maintains a portfolio of community and forum software platforms, including Invision Power Board, Invision Gallery, and related community-management products, that collectively sit deep in web-hosting environments and serve as central gathering places for user-generated content. Despite a narrow product range, the vendor's presence in the landscape reflects the widespread deployment of these platforms across internet-facing community sites. The durable exposure centers on application-layer input handling, recurrring through weakness classes such as cross-site scripting, SQL injection, code injection, and improper input validation—attack surface endemic to web applications that parse and execute user-supplied data. Notably, vulnerabilities affecting this vendor have an elevated tendency to acquire public exploit tooling, reflecting the accessibility and appeal of these platforms as targets for automated web attack. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
73
Total CVEs
More Total CVEs than 99% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Invision Power Services over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 11, 2002
23 years ago
Most Recent CVE
Mar 2, 2010
5,990 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (73 CVEs).

73 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-0802HIGH
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote attackers to execute arbitrary SQL commands via the id parame
Mar 2, 20107.535NOYES
CVE-2005-1598HIGH
SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash)
May 16, 20057.534NOYES
CVE-2004-1531HIGH
SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.
Dec 31, 20047.534NOYES
CVE-2003-1385MEDIUM
ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a
Dec 31, 20036.833NOYES
CVE-2004-1835HIGH
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key,
Dec 31, 20047.530NOYES
CVE-2006-5206HIGH
SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, wh
Oct 10, 20067.529NOYES
CVE-2005-3395HIGH
SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.
Nov 1, 20057.529NOYES
CVE-2004-1836HIGH
SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments
Dec 31, 20047.529NOYES
CVE-2008-0421HIGH
SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command.
Jan 23, 20087.528NOYES
CVE-2007-5688HIGH
Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow rem
Oct 29, 20077.528NOYES
View all 73 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products73 CVEs
58%
40%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown73 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown73 (100.0%)
User Interaction
None0 (0.0%)
Unknown73 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown73 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (73 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
30 CVEs
41.1% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Invision Power Services.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Invision Power Services — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Invision Power Services's Products

View all 1 CNAs →

Top CWEs