Known Vulnerabilities for products from Vbulletin

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Vbulletin".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-9357 json Not Provided 2026-05-24 2026-05-26
CVE-2025-46171 json vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated us... Not Provided 2025-07-23 2026-07-05
CVE-2023-39777 json A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execut... 5.4 - MEDIUM 2023-09-16 2023-09-20
CVE-2023-25135 json vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request tha... 9.8 - CRITICAL 2023-02-03 2023-02-13
CVE-2020-25124 json The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-25123 json The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-25122 json The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-25121 json The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-25120 json The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-25119 json The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-25118 json The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-25117 json The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-25116 json The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-25115 json The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager. 4.8 - MEDIUM 2020-09-03 2020-09-04
CVE-2020-17496 json vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcont... 9.8 - CRITICAL 2020-08-12 2022-10-26
CVE-2020-12720 json vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. 9.8 - CRITICAL 2020-05-08 2022-04-27
CVE-2020-7373 json vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcont... 9.8 - CRITICAL 2020-10-30 2021-07-21
CVE-2019-17271 json vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter. 4.9 - MEDIUM 2019-10-08 2019-10-09
CVE-2019-17132 json vBulletin through 5.5.4 mishandles custom avatars. 9.8 - CRITICAL 2019-10-04 2021-07-21
CVE-2019-17131 json vBulletin before 5.5.4 allows clickjacking. 4.3 - MEDIUM 2019-10-04 2019-10-11

Known software with vulnerabilities from Vbulletin

Type Vendor Product Version
ApplicationVbulletinVbulletin3.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report