📦

vbulletin

Vendor: jelsoft

Actively Exploited 2 CISA KEV List
PoC / Exploits 45 Code Available
Total RCEs 9 Remote Access
Total CVEs 113 Total Indexed
Avg. EPSS 8.83% Exploit Prob.
Latest CVE CVE-2025-46171 Jul 23

Security Vulnerability Index

Page 5 / 12
7.5 CVSS
CVE-2013-6129
Exploit Found

The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013.

EPSS: 51.89%
6.5 CVSS
CVE-2013-3522
Exploit Found

SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.

EPSS: 27.08%
5.8 CVSS

Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter in a lostpw action.

EPSS: 1.53%
7.5 CVSS
CVE-2012-4686
Exploit Found

SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid parameter.

EPSS: 1.11%
10.0 CVSS

Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 through 4.1.12, Forum 4.1.2 through 4.1.12, and the MAPI plugin 1.4.3 for vBulletin 3.x has unknown impact and attack vectors.

EPSS: 2.46%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in vBulletin 4.1.12 allows remote attackers to inject arbitrary web script or HTML via a long string in the subject parameter when creating a post.

EPSS: 1.16%
6.8 CVSS
CVE-2010-1077
Exploit Found

Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the vbseourl parameter.

EPSS: 1.86%
4.3 CVSS
CVE-2009-2172
Exploit Found

Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.

EPSS: 1.16%
4.0 CVSS

The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and pages of an arbitrary thread by toggling a personal sticky.

EPSS: 0.97%
6.5 CVSS

SQL injection vulnerability in admincp/admincalendar.php in vBulletin 3.7.3.pl1 allows remote authenticated administrators to execute arbitrary SQL commands via the holidayinfo[recurring] parameter, a different vector than CVE-2005-3022.

EPSS: 0.96%