Description
Vanilla before 2.6.1 allows XSS via the email field of a profile.
Remediation
References
Related Vulnerabilities
WordPress Plugin Category Specific RSS feed Subscription Cross-Site Request Forgery (2.0)
PostgreSQL Resource Management Errors Vulnerability (CVE-2009-0922)
WordPress Plugin All-in-One WP Migration Remote Code Execution (2.0.2)
WordPress Plugin WP Events Calendar 'event_id' Parameter SQL Injection (6.5.2)