Total vulnerabilities in the database
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.
Software | From | Fixed in |
---|---|---|
vanillaforums / vanilla | 2.6.0 | 2.6.2 |
vanillaforums / vanilla | - | 2.5.5 |