CVE-2019-8279: Vanillaforums Vanilla Forums
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.
Affected products
- Vanillaforums Vanilla Forums: before 2.5.0 (fixed in 2.5.0)
Published 2019-03-02. Last modified 2026-06-17.