Vulnerability index

Browse CVEs

34 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-46171 vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently la… Vbulletin No fix yet Fix from $1,6002025-07-23 HIGH 8.1 CVE-2025-48828EPSS 60% Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting t… Vbulletin No fix yet Fix from $1,9502025-05-27 CRITICAL 9.8 CVE-2025-48827EPSS 77% vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8… Vbulletin after 6.0.3 Fix from $2,3002025-05-27 MEDIUM 5.4 CVE-2023-39777 A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts … Vbulletin after 6.0.0 Fix from $1,6002023-09-16 CRITICAL 9.8 CVE-2023-25135EPSS 24% vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserializati… Vbulletin No fix yet Fix from $2,3002023-02-03 CRITICAL 9.8 CVE-2020-7373EPSS 45% vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.… Vbulletin after 5.6.2 Fix from $2,3002020-10-30 CRITICAL 9.8 CVE-2020-17496 KEVEPSS 88% vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.… Vbulletin after 5.6.2 Fix from $2,3002020-08-12 CRITICAL 9.8 CVE-2020-12720EPSS 89% vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. Vbulletin 5.5.6+ Fix from $2,3002020-05-08 CRITICAL 9.8 CVE-2019-17132EPSS 12% vBulletin through 5.5.4 mishandles custom avatars. Vbulletin after 5.5.4 Fix from $2,3002019-10-04 MEDIUM 6.5 CVE-2019-17130 vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories. Vbulletin after 5.5.4 Fix from $1,6002019-10-04 CRITICAL 9.8 CVE-2019-16759 KEVEPSS 100% vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. Vbulletin after 5.5.4 Fix from $2,3002019-09-24 MEDIUM 6.1 CVE-2018-15493 vBulletin 5.4.3 has an Open Redirect. Vbulletin Patch available Fix from $1,6002018-10-17 MEDIUM 6.1 CVE-2018-6200 vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter. Vbulletin after 4.2.5 Fix from $1,6002018-01-25 CRITICAL 9.8 CVE-2017-17671 vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can… Vbulletin after 5.3.3 Fix from $2,3002017-12-14 CRITICAL 9.8 CVE-2017-17672EPSS 15% In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circum… Vbulletin after 5.3.3 Fix from $2,3002017-12-14 MEDIUM 6.5 CVE-2015-3419 vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vecto… Vbulletin Mitigation only Fix from $1,6002017-09-19 MEDIUM 6.1 CVE-2014-9469 Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3. Vbulletin No fix yet Fix from $1,6002017-08-28 HIGH 8.6 CVE-2017-7569 In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_u… Vbulletin after 5.2.6 Fix from $1,9502017-04-06 HIGH 8.6 CVE-2016-6483EPSS 12% The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch… Vbulletin Patch available Fix from $1,9502016-09-02 CRITICAL 9.8 CVE-2016-6195EPSS 68% SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remo… Vbulletin after 4.2.2 Fix from $2,3002016-08-30 HIGH 7.5 CVE-2015-7808EPSS 81% The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks an… Vbulletin No fix yet Fix from $1,9502015-11-24 MEDIUM 6.8 CVE-2014-9438 Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the authenticatio… Vbulletin No fix yet Fix from $1,6002015-01-02 MEDIUM 5.8 CVE-2014-8670 Open redirect vulnerability in go.php in vBulletin 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attack… Vbulletin No fix yet Fix from $1,6002014-11-06 HIGH 7.1 CVE-2014-2022 SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated us… Vbulletin after 4.2.2 Fix from $1,9502014-10-15 HIGH 7.5 CVE-2014-5102 SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[start… Vbulletin No fix yet Fix from $1,9502014-07-25 HIGH 7.5 CVE-2013-6129EPSS 52% The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password… Vbulletin No fix yet Fix from $1,9502013-10-19 MEDIUM 6.5 CVE-2013-3522EPSS 27% SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated … Vbulletin No fix yet Fix from $1,6002013-05-10 MEDIUM 5.8 CVE-2011-5251 Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and co… Vbulletin after 4.1.3 Fix from $1,6002012-12-31 HIGH 7.5 CVE-2012-4686 SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid … Vbulletin No fix yet Fix from $1,9502012-08-28 HIGH 10.0 CVE-2012-4328 Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 through 4.1.12, Forum 4.1.2 through 4.1.12, and the MAPI plugin 1.4.3 for vBulletin 3.… Mapi No fix yet Fix from $1,9502012-08-14