📦

vbulletin

Vendor: vbulletin

Actively Exploited 2 CISA KEV List
PoC / Exploits 45 Code Available
Total RCEs 9 Remote Access
Total CVEs 426 Total Indexed
Avg. EPSS 8.83% Exploit Prob.
Latest CVE CVE-2025-46171 Jul 23

Security Vulnerability Index

Page 2 / 43
4.8 CVSS

The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI.

EPSS: 0.55%
4.8 CVSS

The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.

EPSS: 0.66%
4.8 CVSS

The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager.

EPSS: 0.55%
4.8 CVSS

The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager.

EPSS: 0.55%
4.8 CVSS

The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.

EPSS: 0.55%
4.8 CVSS

The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.

EPSS: 0.55%
9.8 CVSS
CVE-2020-17496
Exploit Found

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.

EPSS: 87.74%
9.8 CVSS
CVE-2020-12720
Exploit Found

vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

EPSS: 88.95%
4.9 CVSS

vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.

EPSS: 1.45%
9.8 CVSS
CVE-2019-17132
Exploit Found

vBulletin through 5.5.4 mishandles custom avatars.

EPSS: 11.78%