Lussumo maintains Vanilla, a community discussion forum platform whose vulnerability footprint centers on application-layer input-handling and request-validation weaknesses, including cross-site scripting, SQL injection, CSRF, and code-injection flaws typical of web applications that process user-submitted content and render dynamic pages. The recurring weakness classes reflect the inherent challenges of safely parsing and sanitizing forum input across message bodies, user profiles, and administrative interfaces, and public exploit code has frequently been available for vulnerabilities in this product. Defenders deploying Vanilla should prioritize input-validation and output-encoding practices and monitor this vendor's releases for security updates; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lussumo over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1337HIGH Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary | Apr 9, 2010 | 7.5 | 31 | NO | YES |
CVE-2007-5643HIGH Multiple SQL injection vulnerabilities in Lussumo Vanilla 1.1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the CategoryID parameter to ajax/sortca | Oct 23, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-5644HIGH Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthorize | Oct 23, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-3850MEDIUM PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code | Jul 25, 2006 | 5.1 | 23 | NO | YES |
CVE-2009-1845MEDIUM Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the RequestNa | Jun 1, 2009 | 4.3 | 21 | NO | YES |
CVE-2008-3758MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Lussumo Vanilla 1.1.4 and earlier (1) allow remote attackers to inject arbitrary web script or HTML via the NewPassword param | Aug 21, 2008 | 4.3 | 21 | NO | YES |
CVE-2008-3759HIGH Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and earlier has unknown impact and remote attack vectors. | Aug 21, 2008 | 7.5 | 19 | NO | NO |
CVE-2008-3760MEDIUM Cross-site request forgery (CSRF) vulnerability in the sign-out page in Vanilla 1.1.4 and earlier allows remote attackers to hijack the authentication of arbitrary users for reques | Aug 21, 2008 | 4.3 | 15 | NO | NO |
Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML vi | Aug 29, 2008 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lussumo.
Media articles that mention a CVE ID that affects a product developed by Lussumo — matched by CVE ID, not by vendor name.