Launchpad.net

CVE 2019-8279

Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.

See the CVE page on Mitre.org for more details.

References