CVE-2018-19499: Vanillaforums Vanilla
High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.
Affected products
- Vanillaforums Vanilla: before 2.5.5 (fixed in 2.5.5); from 2.6.0, before 2.6.2 (fixed in 2.6.2)
Published 2018-11-23. Last modified 2026-06-17.