VYPR

Vbulletin

by Jelsoft

CVEs (104)

  • CVE-2020-25124MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI.

  • CVE-2020-25123MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager.

  • CVE-2020-25122MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager.

  • CVE-2020-25121MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options.

  • CVE-2020-25120MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI.

  • CVE-2020-25119MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.

  • CVE-2020-25118MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager.

  • CVE-2020-25117MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager.

  • CVE-2020-25116MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.

  • CVE-2020-25115MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.

  • CVE-2019-17131MedOct 4, 2019
    risk 0.28cvss 4.3epss 0.01

    vBulletin before 5.5.4 allows clickjacking.

  • CVE-2015-7808Nov 24, 2015
    risk 0.09cvss epss 0.81

    The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.

  • CVE-2013-6129Oct 19, 2013
    risk 0.07cvss epss 0.52

    The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013.

  • CVE-2005-0511Feb 21, 2005
    risk 0.06cvss epss 0.36

    misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

  • CVE-2013-3522May 10, 2013
    risk 0.05cvss epss 0.27

    SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.

  • CVE-2020-7373CriOct 30, 2020
    risk 0.04cvss 9.8epss 0.45

    vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of…

  • CVE-2002-1660Dec 31, 2002
    risk 0.04cvss epss 0.11

    calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.

  • CVE-2014-2021Oct 25, 2014
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

  • CVE-2014-2022Oct 15, 2014
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.

  • CVE-2012-4686Aug 28, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid parameter.

Page 2 of 6