CVE-2019-8279: Vanillaforums Vanilla Forums

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.

Affected products

Published 2019-03-02. Last modified 2026-06-17.