VYPR

Vendor CVEs

Jelsoft

All CVEs

116 total · sorted by risk
  • CVE-2019-16759CriKEVSep 24, 2019
    risk 0.87cvss 9.8epss 1.00

    vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

  • CVE-2020-17496CriKEVAug 12, 2020
    risk 0.86cvss 9.8epss 0.88

    vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.

  • CVE-2025-48827CriMay 27, 2025
    risk 0.74cvss 10.0epss 0.77

    vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.

  • CVE-2020-12720CriMay 8, 2020
    risk 0.74cvss 9.8epss 0.89

    vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

  • CVE-2016-6195CriAug 30, 2016
    risk 0.72cvss 9.8epss 0.68

    SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in…

  • CVE-2019-17132CriOct 4, 2019
    risk 0.68cvss 9.8epss 0.12

    vBulletin through 5.5.4 mishandles custom avatars.

  • CVE-2017-17672CriDec 14, 2017
    risk 0.68cvss 9.8epss 0.15

    In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which…

  • CVE-2014-2023CriOct 26, 2017
    risk 0.67cvss 9.8epss 0.04

    Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in…

  • CVE-2023-25135CriFeb 3, 2023
    risk 0.66cvss 9.8epss 0.24

    vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors.…

  • CVE-2025-48828CriMay 27, 2025
    risk 0.65cvss 9.0epss 0.60

    Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass…

  • CVE-2017-17671CriDec 14, 2017
    risk 0.64cvss 9.8epss 0.03

    vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is blocked but ..\ traversal is…

  • CVE-2014-9463HigSep 15, 2017
    risk 0.61cvss 8.8epss 0.15

    functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php.

  • CVE-2016-6483HigSep 2, 2016
    risk 0.60cvss 8.6epss 0.12

    The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and 5.2.2 before Patch Level 1…

  • CVE-2017-7569HigApr 6, 2017
    risk 0.56cvss 8.6epss 0.01

    In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.

  • CVE-2019-17130MedOct 4, 2019
    risk 0.42cvss 6.5epss 0.01

    vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.

  • CVE-2015-3419MedSep 19, 2017
    risk 0.42cvss 6.5epss 0.01

    vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vectors related to an input validation failure.

  • CVE-2018-15493MedOct 17, 2018
    risk 0.40cvss 6.1epss 0.01

    vBulletin 5.4.3 has an Open Redirect.

  • CVE-2018-6200MedJan 25, 2018
    risk 0.40cvss 6.1epss 0.03

    vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.

  • CVE-2014-9469MedAug 28, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.

  • CVE-2025-46171MedJul 23, 2025
    risk 0.35cvss 5.4epss 0.00

    vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list can consume excessive memory, exhausting system resources and crashing the forum.

  • CVE-2023-39777MedSep 16, 2023
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts or HTML via the /login.php?do=login url parameter.

  • CVE-2019-17271MedOct 8, 2019
    risk 0.32cvss 4.9epss 0.01

    vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.

  • CVE-2020-25124MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI.

  • CVE-2020-25123MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager.

  • CVE-2020-25122MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager.

  • CVE-2020-25121MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options.

  • CVE-2020-25120MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI.

  • CVE-2020-25119MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.

  • CVE-2020-25118MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager.

  • CVE-2020-25117MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager.

  • CVE-2020-25116MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.

  • CVE-2020-25115MedSep 3, 2020
    risk 0.31cvss 4.8epss 0.01

    The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.

  • CVE-2014-125085MedFeb 6, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in Gimmie Plugin 1.2.2 on vBulletin. Affected is an unknown function of the file trigger_ratethread.php. The manipulation of the argument t/postusername leads to sql injection. Upgrading to version 1.3.0 is able to…

  • CVE-2019-17131MedOct 4, 2019
    risk 0.28cvss 4.3epss 0.01

    vBulletin before 5.5.4 allows clickjacking.

  • CVE-2015-7808Nov 24, 2015
    risk 0.09cvss epss 0.81

    The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.

  • CVE-2013-6129Oct 19, 2013
    risk 0.07cvss epss 0.52

    The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013.

  • CVE-2005-0511Feb 21, 2005
    risk 0.06cvss epss 0.36

    misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

  • CVE-2013-3522May 10, 2013
    risk 0.05cvss epss 0.27

    SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.

  • CVE-2020-7373CriOct 30, 2020
    risk 0.04cvss 9.8epss 0.45

    vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of…

  • CVE-2007-2941May 31, 2007
    risk 0.04cvss epss 0.07

    Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) vbgsitemap/vbgsitemap-config.php or (2)…

  • CVE-2002-1660Dec 31, 2002
    risk 0.04cvss epss 0.11

    calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.

  • CVE-2014-2021Oct 25, 2014
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

  • CVE-2014-2022Oct 15, 2014
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.

  • CVE-2012-4686Aug 28, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid parameter.

  • CVE-2009-2172Jun 23, 2009
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.

  • CVE-2008-4706Oct 23, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php.

  • CVE-2008-3773Aug 22, 2008
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka newpm[title]).

  • CVE-2008-3184Jul 15, 2008
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to…

  • CVE-2008-2744Jun 17, 2008
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10 and 3.7.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors and an "obscure method." NOTE: the vector is probably in the redirect parameter to the Admin Control Panel…

  • CVE-2007-3196Jun 12, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action.

Page 1 of 3