CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Invisioncommunity 1Invisioncommunity Jun 20, 2025 May 16, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeedi...Show more |
1Invisioncommunity 1Invisioncommunity Mar 19, 2025 Jun 7, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter reque...Show more |