Invisioncommunity Invision Power Board vulnerabilities
20 known vulnerabilities affecting invisioncommunity/invision_power_board.
Total CVEs
20
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH6MEDIUM9
Vulnerabilities
Page 1 of 1
CVE-2025-47916CRITICALCVSS 9.8PoC≥ 5.0.0, < 5.0.72025-05-16
CVE-2025-47916 [CRITICAL] CWE-1336 CVE-2025-47916: Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to t
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the
cvelistv5nvd
CVE-2021-39249MEDIUMCVSS 6.1fixed in 4.6.5.12021-08-17
CVE-2021-39249 [MEDIUM] CWE-330 CVE-2021-39249: Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.
nvd
CVE-2021-39250MEDIUMCVSS 5.4fixed in 4.6.5.12021-08-17
CVE-2021-39250 [MEDIUM] CWE-79 CVE-2021-39250: Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resu
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer he
nvd
CVE-2009-5159MEDIUMCVSS 6.1≥ 2.0, ≤ 3.0.42020-03-13
CVE-2009-5159 [MEDIUM] CWE-79 CVE-2009-5159: Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allo
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
nvd
CVE-2013-3725CRITICALCVSS 9.8fixed in 4.0.02020-02-12
CVE-2013-3725 [CRITICAL] CVE-2013-3725: Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
nvd
CVE-2012-2226CRITICALCVSS 9.8PoCfixed in 3.3.12020-01-09
CVE-2012-2226 [CRITICAL] CWE-434 CVE-2012-2226: Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote att
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
nvd
CVE-2019-8278MEDIUMCVSS 6.1≥ 3.3.1, ≤ 3.4.82019-03-02
CVE-2019-8278 [MEDIUM] CWE-79 CVE-2019-8278: Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
nvd
CVE-2014-4928HIGHCVSS 8.8fixed in 3.4.62018-03-20
CVE-2014-4928 [HIGH] CWE-89 CVE-2014-4928: SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the cId parameter.
nvd
CVE-2017-8898CRITICALCVSS 9.8≤ 4.1.19.22017-05-11
CVE-2017-8898 [CRITICAL] CWE-79 CVE-2017-8898: Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcemen
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the "<> Source" option.
nvd
CVE-2017-8899HIGHCVSS 8.1≤ 4.1.19.22017-05-11
CVE-2017-8899 [HIGH] CWE-79 CVE-2017-8899: Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power Board user and can be used to gain access to moderator/admin accounts. The primary cause is the ability to upload an SVG document with a
nvd
CVE-2017-8897MEDIUMCVSS 6.1≤ 4.1.19.22017-05-11
CVE-2017-8897 [MEDIUM] CWE-79 CVE-2017-8897: Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a malicious announcement affecting any Invision Power Board user who views the announcement.
nvd
CVE-2016-2564MEDIUMCVSS 5.9≤ 4.1.8.12017-04-23
CVE-2016-2564 [MEDIUM] CWE-331 CVE-2016-2564: Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.
nvd
CVE-2016-6174HIGHCVSS 8.1PoC≤ 4.1.12.32016-07-12
CVE-2016-6174 [HIGH] CVE-2016-6174: applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (a
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.
nvd
CVE-2015-6812HIGHCVSS 7.8≤ 4.0.112015-09-04
CVE-2015-6812 [HIGH] CWE-399 CVE-2015-6812: Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4
Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial of service (loop and memory consumption) via a crafted URL.
nvd
CVE-2014-9239HIGHCVSS 7.5v3.3.0v3.3.1+10 more2014-12-03
CVE-2014-9239 [HIGH] CWE-89 CVE-2014-9239: SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invi
SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[] parameter.
nvd
CVE-2014-5106MEDIUMCVSS 4.3v3.4.0v3.4.1+5 more2014-07-28
CVE-2014-5106 [MEDIUM] CWE-79 CVE-2014-5106: Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x t
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to admin/install/index.php.
nvd
CVE-2014-3149MEDIUMCVSS 4.3v3.3.0v3.3.1+10 more2014-07-03
CVE-2014-3149 [MEDIUM] CWE-79 CVE-2014-3149: Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x a
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded before 20140424, or IP.Nexus 1.5.x through 1.5.9, as downloaded before 20140424, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-5692CRITICALCVSS 10.0PoCv3.1.2v3.3.02012-10-31
CVE-2012-5692 [CRITICAL] CVE-2012-5692: Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Boar
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and remote attack vectors.
nvd
CVE-2010-3424MEDIUMCVSS 4.3v3.1.22010-09-16
CVE-2010-3424 [MEDIUM] CWE-79 CVE-2010-3424: Cross-site scripting (XSS) vulnerability in admin/sources/classes/bbcode/custom/defaults.php in Invi
Cross-site scripting (XSS) vulnerability in admin/sources/classes/bbcode/custom/defaults.php in Invision Power Board (IP.Board) 3.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-3974HIGHCVSS 7.5v3.0.0v3.0.1+1 more2009-11-18
CVE-2009-3974 [HIGH] CWE-89 CVE-2009-3974: Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3
Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) search_term parameter to admin/applications/core/modules_public/search/search.php and (2) aid parameter to admin/applications/core/modules_public/global/lostpass.php. NOTE: on 200908
nvd