← Vulnerability feed

Vulnerability record · CVE-2017-8898 · published 11 May 2017

CVE-2017-8898: Invisioncommunity invision power board cross-site scripting vulnerability

IInvisioncommunity · Invision Power Board

Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the "<> Source" option.

9.8 CVSS 3.0 Critical EPSS 1.9% · top 21.3% CWE-79 · Cross-site scripting
9.8CVSS 3.0 base score, v2 7.5
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the "<> Source" option.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-8898 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-5692Invisioncommunity invision power board vulnerabilityUnspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and rem…EPSS 26%9.8CVE-2013-3725Invisioncommunity invision power board vulnerabilityInvision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.EPSS 1.8%9.8CVE-2012-2226Invisioncommunity invision power board unrestricted file upload vulnerabilityInvision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute…EPSS 7.4%8.8CVE-2014-4928Invisioncommunity invision power board sql injection vulnerabilitySQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via …EPSS 1.1%8.1CVE-2017-8899Invisioncommunity invision power board cross-site scripting vulnerabilityInvision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments…EPSS 1.5%8.1CVE-2016-6174Invisioncommunity invision power board vulnerabilityapplications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) bef…EPSS 12%7.8CVE-2015-6812Invisioncommunity invision power board vulnerabilityInvision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial…EPSS 1.4%7.5CVE-2014-9239Invisioncommunity invision power board sql injection vulnerabilitySQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and …EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2017-8898), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.