Vanilla Forums operates a community discussion and engagement platform that, despite a narrow product portfolio, occupies a prominent position in the self-hosted forum and discussion software landscape. Vulnerabilities affecting the vendor skew toward serious outcomes with a meaningful share reaching critical severity and frequently acquire public exploit code, driven by the platform's web-facing nature and the appeal of forum installations as targets for account compromise and content manipulation. The exposure recurs across its core Vanilla Forums product and related components through weakness classes centered on web input handling: cross-site scripting, SQL injection, information disclosure, and authorization bypass are characteristic of the application-layer attack surface presented by community platforms. Defenders should prioritize patching this vendor's releases, particularly for internet-accessible installations, and inventory forum versions in use; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vanillaforums over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10073HIGH The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive i | May 23, 2017 | 7.5 | 85 | NO | YES |
CVE-2017-1000432HIGH Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access | Jan 2, 2018 | 8.0 | 35 | NO | YES |
CVE-2018-18903CRITICAL Vanilla 2.6.x before 2.6.4 allows remote code execution. | Nov 3, 2018 | 9.8 | 33 | NO | NO |
CVE-2020-8825MEDIUM index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. | Feb 10, 2020 | 5.4 | 31 | NO | YES |
CVE-2011-3614CRITICAL An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9. | Jan 22, 2020 | 9.8 | 31 | NO | NO |
CVE-2013-3528HIGH Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection." | May 10, 2013 | 7.5 | 30 | NO | YES |
CVE-2013-3527HIGH Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter name in the Form/Email array to | May 10, 2013 | 7.5 | 29 | NO | YES |
CVE-2011-3613HIGH An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled. | Jan 22, 2020 | 7.5 | 25 | NO | NO |
CVE-2012-6557MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) AboutMe | May 23, 2013 | 4.3 | 25 | NO | YES |
CVE-2012-6555MEDIUM Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title. | May 23, 2013 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vanillaforums.
Media articles that mention a CVE ID that affects a product developed by Vanillaforums — matched by CVE ID, not by vendor name.