Critical severity9.8NVD Advisory· Published May 8, 2020· Updated Jun 17, 2026
CVE-2020-12720
CVE-2020-12720
Description
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*range: >=5.0.0,<5.5.6
- cpe:2.3:a:vbulletin:vbulletin:5.5.6:-:*:*:*:*:*:*
- cpe:2.3:a:vbulletin:vbulletin:5.6.0:-:*:*:*:*:*:*
- cpe:2.3:a:vbulletin:vbulletin:5.6.1.-:*:*:*:*:*:*:*
- (no CPE)range: <5.5.6pl1, <5.6.0pl1, <5.6.1pl1
- vBulletin/vBulletindescription
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/157716/vBulletin-5.6.1-SQL-Injection.htmlnvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/157904/vBulletin-5.6.1-SQL-Injection.htmlnvdThird Party AdvisoryVDB Entry
- attackerkb.com/topics/RSDAFLik92/cve-2020-12720-vbulletin-incorrect-access-controlnvdThird Party Advisory
- forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4440032-vbulletin-5-6-1-security-patch-level-1nvdVendor Advisory
News mentions
0No linked articles in our index yet.