← Vulnerability feed

Vulnerability record · CVE-2012-2226 · published 9 January 2020

CVE-2012-2226: Invisioncommunity invision power board unrestricted file upload vulnerability

IInvisioncommunity · Invision Power Board

Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.

9.8 CVSS 3.1 Critical EPSS 7.4% · top 5.8% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
7.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/52998 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/74855 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/52998 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/74855 Third Party AdvisoryVDB Entry

Track CVE-2012-2226 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-5692Invisioncommunity invision power board vulnerabilityUnspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and rem…EPSS 26%9.8CVE-2013-3725Invisioncommunity invision power board vulnerabilityInvision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.EPSS 1.8%9.8CVE-2017-8898Invisioncommunity invision power board cross-site scripting vulnerabilityInvision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invisio…EPSS 1.9%8.8CVE-2014-4928Invisioncommunity invision power board sql injection vulnerabilitySQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via …EPSS 1.1%8.1CVE-2017-8899Invisioncommunity invision power board cross-site scripting vulnerabilityInvision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments…EPSS 1.5%8.1CVE-2016-6174Invisioncommunity invision power board vulnerabilityapplications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) bef…EPSS 12%7.8CVE-2015-6812Invisioncommunity invision power board vulnerabilityInvision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial…EPSS 1.4%7.5CVE-2014-9239Invisioncommunity invision power board sql injection vulnerabilitySQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and …EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2012-2226), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.