Vbulletin

Vbulletin

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht Exploit
  • EPSS 1.72%
  • Veröffentlicht 27.07.2026 12:39:16
  • Zuletzt bearbeitet 07.08.2026 06:16:56

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supply...

  • EPSS 0.28%
  • Veröffentlicht 24.05.2026 05:15:09
  • Zuletzt bearbeitet 23.07.2026 11:10:00

A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 23.07.2025 00:00:00
  • Zuletzt bearbeitet 05.07.2026 01:21:47

vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list can consume excessive memory, exhausting system resources and cra...

Medienbericht Exploit
  • EPSS 60.4%
  • Veröffentlicht 27.05.2025 00:00:00
  • Zuletzt bearbeitet 25.06.2025 16:32:38

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax,...

Medienbericht Exploit
  • EPSS 77.46%
  • Veröffentlicht 27.05.2025 00:00:00
  • Zuletzt bearbeitet 25.06.2025 16:46:46

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 16.09.2023 01:15:08
  • Zuletzt bearbeitet 21.11.2024 08:15:55

A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts or HTML via the /login.php?do=login url parameter.

Exploit
  • EPSS 23.93%
  • Veröffentlicht 03.02.2023 05:15:10
  • Zuletzt bearbeitet 26.03.2025 15:15:47

vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize an...

Exploit
  • EPSS 45.01%
  • Veröffentlicht 30.10.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:37:07

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 03.09.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 05:17:24

The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI.

Exploit
  • EPSS 0.55%
  • Veröffentlicht 03.09.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 05:17:24

The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager.