Product
invisioncommunity invision power board
27 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-47916
CVE-2024-30163
CVE-2021-40604
CVE-2021-39250
CVE-2021-39249
CVE-2021-32924
CVE-2021-3025
CVE-2021-3026
CVE-2020-29477
CVE-2009-5159
CVE-2013-3725
CVE-2012-2226
CVE-2019-8278
CVE-2014-4928
CVE-2017-8899
CVE-2017-8898
CVE-2017-8897
CVE-2016-2564
CVE-2016-6174
CVE-2015-6812
CVE-2014-9239
CVE-2014-5106
CVE-2014-3149
CVE-2012-5692
CVE-2010-3424
CVE-2009-3974
CVE-2005-1947
>= 5.0.0 and < 5.0.7
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies
>= 4.4.0 and < 4.7.16
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\fr
< 4.6.2
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to reques
< 4.6.5.1
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because
< 4.6.5.1
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded fil
< 4.6.0
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\
< 4.5.4.2
Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a
< 4.5.4.2
Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment.
all versions
Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attack
>= 2.0 and <= 3.0.4
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
< 4.0.0
Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
< 3.3.1
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive inf
>= 3.3.1 and <= 3.4.8
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
< 3.4.6
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrar
<= 4.1.19.2
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues
<= 4.1.19.2
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalat
<= 4.1.19.2
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: a
<= 4.1.8.1
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function witho
<= 4.1.12.3
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB,
<= 4.0.11
Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attacker
all versions
SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or I
all versions
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows remote att
all versions
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as dow
all versions
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unk
all versions
Cross-site scripting (XSS) vulnerability in admin/sources/classes/bbcode/custom/defaults.php in Invision Power Board (IP.Board) 3.
all versions
Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to
< 1.3.1
Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and imag