CVE-2025-47916 | invisioncommunity Invision Power Board up to 5.0.6 Template String themeeditor.php makeProcessFunction special elements used in a template engine (EUVD-2025-15448 / EDB-52294)
A vulnerability was found in invisioncommunity Invision Power Board up to 5.0.6. It has been declared as critical. Affected by this vulnerability is the function Theme::makeProcessFunction of the file themeeditor.php of the component Template String Handler. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is known as CVE-2025-47916. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.