CVE-2012-2226: Invisioncommunity Invision Power Board

Critical severity, CVSS 9.8. EPSS: 7.4% chance of exploitation in the next 30 days.

Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.

Affected products

Published 2020-01-09. Last modified 2026-06-16.