---
id: CVE-2020-29477
title: >-
  Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the
  Field Name field
summary: >-
  Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the
  Field Name field. This vulnerability can allow an attacker to inject the XSS
  payload in Field Name and each time any user will open that, the XSS triggers
  and the …
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: invisioncommunity
product: community
affected:
  - community = 4.5.4
published: '2020-12-30'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-29477'
references:
  - url: 'https://www.exploit-db.com/exploits/49188'
    label: cve@mitre.org
  - url: 'http://invision.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/49188'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.01091
epssPercentile: 0.63964
exploitAvailable: true
ingestedAt: '2026-07-05T00:59:25.593Z'
exploits:
  exploitdb: true
  checkedAt: '2026-09-24T07:52:47.137Z'
---

## Overview

Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

## Affected

- `community = 4.5.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
