Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2020-8825 — VanillaForum 2.6.3 allows stored XSS. | Kitploit
Tools/GitHubGitHub/hacky1997/cve-2020-8825
Phishing ToolsVulnerability AnalysisWeb Application ExploitationPenetration TestingLearning & Education
GitHubhacky1997/cve-2020-8825

CVE-2020-8825

VanillaForum 2.6.3 allows stored XSS.

View Repository
333 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

CVE-2020-8825

cve

Publish:

CVE-2020-8825

Vendor:

root@kitploit:~
PHP VanillaForum 

Description:

root@kitploit:~
The vulnerability exists due to insufficient sanitization of user-supplied data passed to "index.php?p=/dashboard/settings/branding" URL. A remote attacker can permanently inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Environment:

root@kitploit:~
Version: 2.6.3
OS: Windows 10, Linux
PHP: 7
URL: index.php?p=/dashboard/settings/branding
   

Proof of Concept:

vanilla

Assigned by:

Sayak Naskar

Download Tool