Product
invisioncommunity ips community suite
4 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-40604
CVE-2021-32924
CVE-2021-3025
CVE-2021-3026
< 4.6.2
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to reques
< 4.6.0
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\
< 4.5.4.2
Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a
< 4.5.4.2
Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment.