CVE-2018-18903: Vanillaforums Vanilla
Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.
Vanilla 2.6.x before 2.6.4 allows remote code execution.
Affected products
- Vanillaforums Vanilla: from 2.6.0, before 2.6.4 (fixed in 2.6.4)
Published 2018-11-03. Last modified 2026-06-17.