Vbulletin

    Dashboard / Vendors

    Products: 5
    Vulnerabilities: 56
    Known Exploited: 2
    13
    Critical Level Threats
    10
    High Level Threats
    31
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-61511

    vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php

    Last Modified: Jul 29, 2026
    Published: Jul 27, 2026

    CVE-2026-9357

    vBulletin Login cross site scripting

    Last Modified: May 26, 2026
    Published: May 24, 2026

    CVE-2025-46171

    vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list can consume excessive memory, exhausting system resources and crashing the forum.

    Last Modified: Jul 28, 2025
    Published: Jul 23, 2025

    CVE-2025-48827

    vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.

    Last Modified: Jun 25, 2025
    Published: May 27, 2025

    CVE-2025-48828

    Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.

    Last Modified: Jun 25, 2025
    Published: May 27, 2025
    Items Per Page