Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Vbulletin MEDIUM 5.4
CVE-2025-46171

vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently la…

No fix yet
Fix from $1,600 2025-07-23
Vbulletin HIGH 8.1
CVE-2025-48828EPSS 60%

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting t…

No fix yet
Fix from $1,950 2025-05-27
Vbulletin CRITICAL 9.8
CVE-2023-25135EPSS 24%

vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserializati…

No fix yet
Fix from $2,300 2023-02-03
Vbulletin MEDIUM 6.5
CVE-2015-3419

vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vecto…

Mitigation only
Fix from $1,600 2017-09-19
Vbulletin MEDIUM 6.1
CVE-2014-9469

Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.

No fix yet
Fix from $1,600 2017-08-28
Vbulletin HIGH 7.5
CVE-2015-7808EPSS 81%

The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks an…

No fix yet
Fix from $1,950 2015-11-24
Vbulletin MEDIUM 6.8
CVE-2014-9438

Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the authenticatio…

No fix yet
Fix from $1,600 2015-01-02
Vbulletin MEDIUM 5.8
CVE-2014-8670

Open redirect vulnerability in go.php in vBulletin 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attack…

No fix yet
Fix from $1,600 2014-11-06
Vbulletin HIGH 7.5
CVE-2014-5102

SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[start…

No fix yet
Fix from $1,950 2014-07-25
Vbulletin HIGH 7.5
CVE-2013-6129EPSS 52%

The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password…

No fix yet
Fix from $1,950 2013-10-19
Vbulletin MEDIUM 6.5
CVE-2013-3522EPSS 27%

SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated …

No fix yet
Fix from $1,600 2013-05-10
Vbulletin HIGH 7.5
CVE-2012-4686

SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid …

No fix yet
Fix from $1,950 2012-08-28
Mapi HIGH 10.0
CVE-2012-4328

Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 through 4.1.12, Forum 4.1.2 through 4.1.12, and the MAPI plugin 1.4.3 for vBulletin 3.…

No fix yet
Fix from $1,950 2012-08-14
Vbulletin MEDIUM 6.5
CVE-2008-6255

Multiple SQL injection vulnerabilities in vBulletin 3.7.4 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) ans…

Mitigation only
Fix from $1,600 2009-02-24
Vbulletin MEDIUM 6.5
CVE-2008-6256

SQL injection vulnerability in admincp/admincalendar.php in vBulletin 3.7.3.pl1 allows remote authenticated administrators to execute arbitrary SQL c…

No fix yet
Fix from $1,600 2009-02-24
Vbgooglemap HIGH 7.5
CVE-2008-4706

SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via t…

No fix yet
Fix from $1,950 2008-10-23
Vbulletin HIGH 7.5
CVE-2008-2460

SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter in a sea…

No fix yet
Fix from $1,950 2008-05-27