Known Vulnerabilities for products from Vbulletin
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Vbulletin".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-9357 json | Not Provided | 2026-05-24 | 2026-05-26 | |
| CVE-2025-46171 json | vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated us... | Not Provided | 2025-07-23 | 2026-07-05 |
| CVE-2023-39777 json | A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execut... | 5.4 - MEDIUM | 2023-09-16 | 2023-09-20 |
| CVE-2023-25135 json | vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request tha... | 9.8 - CRITICAL | 2023-02-03 | 2023-02-13 |
| CVE-2020-25124 json | The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-25123 json | The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-25122 json | The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-25121 json | The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-25120 json | The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-25119 json | The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-25118 json | The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-25117 json | The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-25116 json | The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-25115 json | The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager. | 4.8 - MEDIUM | 2020-09-03 | 2020-09-04 |
| CVE-2020-17496 json | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcont... | 9.8 - CRITICAL | 2020-08-12 | 2022-10-26 |
| CVE-2020-12720 json | vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. | 9.8 - CRITICAL | 2020-05-08 | 2022-04-27 |
| CVE-2020-7373 json | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcont... | 9.8 - CRITICAL | 2020-10-30 | 2021-07-21 |
| CVE-2019-17271 json | vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter. | 4.9 - MEDIUM | 2019-10-08 | 2019-10-09 |
| CVE-2019-17132 json | vBulletin through 5.5.4 mishandles custom avatars. | 9.8 - CRITICAL | 2019-10-04 | 2021-07-21 |
| CVE-2019-17131 json | vBulletin before 5.5.4 allows clickjacking. | 4.3 - MEDIUM | 2019-10-04 | 2019-10-11 |
Known software with vulnerabilities from Vbulletin
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Vbulletin | Vbulletin | 3.0.0 |