Vbulletin
by Jelsoft
CVEs (104)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-25124 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI. | ||
| CVE-2020-25123 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager. | ||
| CVE-2020-25122 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager. | ||
| CVE-2020-25121 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options. | ||
| CVE-2020-25120 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI. | ||
| CVE-2020-25119 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual. | ||
| CVE-2020-25118 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager. | ||
| CVE-2020-25117 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager. | ||
| CVE-2020-25116 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager. | ||
| CVE-2020-25115 | Med | 0.31 | 4.8 | 0.01 | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager. | ||
| CVE-2019-17131 | Med | 0.28 | 4.3 | 0.01 | Oct 4, 2019 | vBulletin before 5.5.4 allows clickjacking. | ||
| CVE-2015-7808 | 0.09 | — | 0.81 | Nov 24, 2015 | The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments. | |||
| CVE-2013-6129 | 0.07 | — | 0.52 | Oct 19, 2013 | The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013. | |||
| CVE-2005-0511 | 0.06 | — | 0.36 | Feb 21, 2005 | misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter. | |||
| CVE-2013-3522 | 0.05 | — | 0.27 | May 10, 2013 | SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter. | |||
| CVE-2020-7373 | Cri | 0.04 | 9.8 | 0.45 | Oct 30, 2020 | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of… | ||
| CVE-2002-1660 | 0.04 | — | 0.11 | Dec 31, 2002 | calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter. | |||
| CVE-2014-2021 | 0.03 | — | 0.03 | Oct 25, 2014 | Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name. | |||
| CVE-2014-2022 | 0.03 | — | 0.03 | Oct 15, 2014 | SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request. | |||
| CVE-2012-4686 | 0.03 | — | 0.01 | Aug 28, 2012 | SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid parameter. |
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI.
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager.
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager.
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options.
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI.
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager.
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager.
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.
- risk 0.31cvss 4.8epss 0.01
The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.
- risk 0.28cvss 4.3epss 0.01
vBulletin before 5.5.4 allows clickjacking.
- CVE-2015-7808Nov 24, 2015risk 0.09cvss —epss 0.81
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.
- CVE-2013-6129Oct 19, 2013risk 0.07cvss —epss 0.52
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013.
- CVE-2005-0511Feb 21, 2005risk 0.06cvss —epss 0.36
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
- CVE-2013-3522May 10, 2013risk 0.05cvss —epss 0.27
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.
- risk 0.04cvss 9.8epss 0.45
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of…
- CVE-2002-1660Dec 31, 2002risk 0.04cvss —epss 0.11
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
- CVE-2014-2021Oct 25, 2014risk 0.03cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.
- CVE-2014-2022Oct 15, 2014risk 0.03cvss —epss 0.03
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.
- CVE-2012-4686Aug 28, 2012risk 0.03cvss —epss 0.01
SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid parameter.
Page 2 of 6