CVE-2018-19499: Vanillaforums Vanilla

High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.

Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.

Affected products

  • Vanillaforums Vanilla: before 2.5.5 (fixed in 2.5.5); from 2.6.0, before 2.6.2 (fixed in 2.6.2)

Published 2018-11-23. Last modified 2026-06-17.