CVE-2015-6812

high
Published 2015-09-04 · Modified 2026-05-06
CVSS v3
CVSS v2
7.8
VIR risk
7.8

Description

Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial of service (loop and memory consumption) via a crafted URL.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://community.invisionpower.com/release-notes/40121-r22/

Application impact

VendorProductVersionsFixed
invisioncommunityinvision_power_board{"endIncluding":"4.0.11"}

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.