Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-46171 vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently la… Vbulletin No fix yet Fix from $1,6002025-07-23 HIGH 8.1 CVE-2025-48828EPSS 60% Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting t… Vbulletin No fix yet Fix from $1,9502025-05-27 CRITICAL 9.8 CVE-2023-25135EPSS 24% vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserializati… Vbulletin No fix yet Fix from $2,3002023-02-03 MEDIUM 6.5 CVE-2015-3419 vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vecto… Vbulletin Mitigation only Fix from $1,6002017-09-19 MEDIUM 6.1 CVE-2014-9469 Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3. Vbulletin No fix yet Fix from $1,6002017-08-28 HIGH 7.5 CVE-2015-7808EPSS 81% The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks an… Vbulletin No fix yet Fix from $1,9502015-11-24 MEDIUM 6.8 CVE-2014-9438 Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the authenticatio… Vbulletin No fix yet Fix from $1,6002015-01-02 MEDIUM 5.8 CVE-2014-8670 Open redirect vulnerability in go.php in vBulletin 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attack… Vbulletin No fix yet Fix from $1,6002014-11-06 HIGH 7.5 CVE-2014-5102 SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[start… Vbulletin No fix yet Fix from $1,9502014-07-25 HIGH 7.5 CVE-2013-6129EPSS 52% The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password… Vbulletin No fix yet Fix from $1,9502013-10-19 MEDIUM 6.5 CVE-2013-3522EPSS 27% SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated … Vbulletin No fix yet Fix from $1,6002013-05-10 HIGH 7.5 CVE-2012-4686 SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid … Vbulletin No fix yet Fix from $1,9502012-08-28 HIGH 10.0 CVE-2012-4328 Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 through 4.1.12, Forum 4.1.2 through 4.1.12, and the MAPI plugin 1.4.3 for vBulletin 3.… Mapi No fix yet Fix from $1,9502012-08-14 MEDIUM 6.5 CVE-2008-6255 Multiple SQL injection vulnerabilities in vBulletin 3.7.4 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) ans… Vbulletin Mitigation only Fix from $1,6002009-02-24 MEDIUM 6.5 CVE-2008-6256 SQL injection vulnerability in admincp/admincalendar.php in vBulletin 3.7.3.pl1 allows remote authenticated administrators to execute arbitrary SQL c… Vbulletin No fix yet Fix from $1,6002009-02-24 HIGH 7.5 CVE-2008-4706 SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via t… Vbgooglemap No fix yet Fix from $1,9502008-10-23 HIGH 7.5 CVE-2008-2460 SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter in a sea… Vbulletin No fix yet Fix from $1,9502008-05-27