shouldiuse.io

Categories

VERDICT

Should I use Invision Community?

Forum and community platform with forums, gallery, calendar, and commerce apps - invisioncommunity.com

Depends. Buy if you run a serious, growing community and can keep up with security patches; the suite is genuinely deep. Skip it for a small board or shoestring budget — it is heavy and its CVE record demands active patching.

Confidence

Medium. Based on 15+ public sources; review snippets partly truncated.

Ratings

  • Value for money
  • Ease of useNo usability evidence found
  • Feature depth
  • Support quality
  • Security posture

Pricing

Not disclosed

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Large brand or hobbyist communities
  • All-in-one forums, gallery, and commerce
  • Self-hosters wanting full control

Not for

  • Small teams wanting a simple board — this is a heavy suite
  • Anyone who won't patch fast — active RCE CVEs
  • Budget buyers; licensing plus hosting adds up
  • Zero-maintenance SaaS seekers on Classic self-hosted

Gotchas - check before you buy

high

27 public CVEs; unauthenticated RCE affected v5.0.6 (May 2025). Patch fast or risk compromise

medium

Self-hosted Classic means you own hosting, updates, and security yourself

medium

Licensing plus hosting costs stack up; complaint threads call pricing greedy

medium

Migrating legacy 4.x data to v5 or rivals like Discourse is painful

Pros and cons

Pros

  • Mature all-in-one suite: forums, calendar, gallery, commerce
  • Self-hosted Classic option gives full control
  • Active development; v5 released Feb 2025 with frequent updates
  • Native iOS and Android apps available
  • Trusted by major nonprofits like The Trevor Project

Cons

  • Recurring critical vulnerabilities: unauthenticated RCE and SQL injections
  • Complaint threads accuse the vendor of shady, greedy practices
  • Old 4.x boards are hard to migrate or resurrect
  • Capterra reviewer lists features that need improvement
  • Users actively debate switching to Discourse or XenForo

Sources & method

Analyzed 9/29/2026 - 15 sources - 27 CVEs including critical 2024–2025 RCEs and SQL injections; vendor ships regular security patches.

official x4review x6security x4news x1
  • CVE-2025-47916 — remote code execution, Critical RCE in Invision Community; vendor released security updates for 4.7.20 and 5.0.7 in May 2025.
  • Unauthenticated RCE via template injection (≤5.0.6), Remote attackers could execute code without authentication on affected 5.0.x versions.
  • SQL injection in store.php (≤4.7.15), CVE-2024-30162 — SQL injection exploitable in the store component.
  • SQL injection in calendar/view.php (≤4.7.20), Publicly disclosed SQL injection with exploit code published July 2025.

Key stats

  • Value for money: 2/5

    Rating

  • Not disclosed

    Starting price

  • 15

    Sources

  • Analyzed

  • Value for money: 2/5. Complaint threads call its licensing greedy
  • Ease of use. No usability evidence found
  • Feature depth: 4/5. Suite covers forums, gallery, calendar, commerce, pages
  • Support quality: 2/5. Ticket and forum support; complaint threads exist
  • Security posture: 2/5. Recurring RCE and SQLi CVEs, though patched
  • 27 Public CVEs OpenCVE database listings
  • 5.0.10 Latest version Released July 2025
  • 2 Deployment options Cloud or self-hosted Classic
  • 4 Pricing tiers Per TrustRadius listing

Pricing

Not disclosed

Security

27 CVEs including critical 2024–2025 RCEs and SQL injections; vendor ships regular security patches.

  • CVE-2025-47916 — remote code executionCritical RCE in Invision Community; vendor released security updates for 4.7.20 and 5.0.7 in May 2025.⁷
  • Unauthenticated RCE via template injection (≤5.0.6)Remote attackers could execute code without authentication on affected 5.0.x versions.⁶
  • SQL injection in store.php (≤4.7.15)CVE-2024-30162 — SQL injection exploitable in the store component.⁸
  • SQL injection in calendar/view.php (≤4.7.20)Publicly disclosed SQL injection with exploit code published July 2025.⁹

What users say

Split: users value the deep feature set, but forum threads complain about licensing practices, costs, and migration pain.

“Stay away from Invision Power Services and their products”
TheAdminZone forum thread title
“Resurrecting old Invision Board from 2008 to new forum?”
Reddit, r/webdev

Companies that use it

  • The Trevor Project⁵
Full analysis

Based on 15+ public sources; review snippets partly truncated.

Powerful, mature forum suite with recurring CVEs — right for serious communities, overkill for small boards.

Methodology

Based on 15+ public sources; review snippets partly truncated.

Sources

  1. news
  2. Platform Featuresinvisioncommunity.com
    official
  3. Pricinginvisioncommunity.com
    official
  4. official
  5. Case Study: The Trevor Projectinvisioncommunity.com
    official
  6. security
  7. CVE-2025-47916 RCE — Qualysthreatprotect.qualys.com
    security
  8. security
  9. security
  10. review
  11. Trustpilot reviewstrustpilot.com
    review
  12. Capterra reviewscapterra.co.uk
    review
  13. TrustRadius pricingtrustradius.com
    review
  14. review
  15. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.