CVE-2012-4954: Vanillaforums Vanilla

Low severity, CVSS 3.5. EPSS: 1.1% chance of exploitation in the next 30 days.

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

Affected products

  • Vanillaforums Vanilla: up to and including 2.0.18.4; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …
  • Vanillaforums Vanilla Forums: up to and including 2.1

Published 2012-11-15. Last modified 2026-06-16.