Invision Power Services maintains a portfolio of community and forum software platforms, including Invision Power Board, Invision Gallery, and related community-management products, that collectively sit deep in web-hosting environments and serve as central gathering places for user-generated content. Despite a narrow product range, the vendor's presence in the landscape reflects the widespread deployment of these platforms across internet-facing community sites. The durable exposure centers on application-layer input handling, recurrring through weakness classes such as cross-site scripting, SQL injection, code injection, and improper input validation—attack surface endemic to web applications that parse and execute user-supplied data. Notably, vulnerabilities affecting this vendor have an elevated tendency to acquire public exploit tooling, reflecting the accessibility and appeal of these platforms as targets for automated web attack. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Invision Power Services over time
Signals from CVEs in this vendor scope (73 CVEs).
73 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0802HIGH SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote attackers to execute arbitrary SQL commands via the id parame | Mar 2, 2010 | 7.5 | 35 | NO | YES |
CVE-2005-1598HIGH SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) | May 16, 2005 | 7.5 | 34 | NO | YES |
CVE-2004-1531HIGH SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter. | Dec 31, 2004 | 7.5 | 34 | NO | YES |
CVE-2003-1385MEDIUM ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a | Dec 31, 2003 | 6.8 | 33 | NO | YES |
CVE-2004-1835HIGH Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, | Dec 31, 2004 | 7.5 | 30 | NO | YES |
CVE-2006-5206HIGH SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, wh | Oct 10, 2006 | 7.5 | 29 | NO | YES |
CVE-2005-3395HIGH SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter. | Nov 1, 2005 | 7.5 | 29 | NO | YES |
CVE-2004-1836HIGH SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments | Dec 31, 2004 | 7.5 | 29 | NO | YES |
CVE-2008-0421HIGH SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command. | Jan 23, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-5688HIGH Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow rem | Oct 29, 2007 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (73 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Invision Power Services.
Media articles that mention a CVE ID that affects a product developed by Invision Power Services — matched by CVE ID, not by vendor name.