Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vbulletin vbulletin 4.2.2 vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2014-9469
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.
Vbulletin Vbulletin 3.8.7
Vbulletin Vbulletin 4.2.2
Vbulletin Vbulletin 5.0.5
Vbulletin Vbulletin 5.1.3
Vbulletin Vbulletin 3.6
Vbulletin Vbulletin 3.5.4
Vbulletin Vbulletin 3.6.7
8.6
CVSSv3
CVE-2016-6483
The media-file upload feature in vBulletin prior to 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x prior to 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x prior to 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and 5.2.2 before Patch Leve...
Vbulletin Vbulletin 4.2.3
Vbulletin Vbulletin 3.8.8
Vbulletin Vbulletin 5.2.2
Vbulletin Vbulletin 4.2.2
Vbulletin Vbulletin 3.8.9
Vbulletin Vbulletin 3.8.7
Vbulletin Vbulletin 5.2.0
Vbulletin Vbulletin 5.2.1
1 EDB exploit
1 Article
NA
CVE-2014-9438
Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote malicious users to hijack the authentication of administrators for requests that (1) ban a user via the username parameter in a dobanuser action to modcp/banning.php or...
Vbulletin Vbulletin 4.2.2
NA
CVE-2014-2021
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and previous versions, and 5.0.x up to and including 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client...
Vbulletin Vbulletin 5.0.4
Vbulletin Vbulletin 5.0.3
Vbulletin Vbulletin
Vbulletin Vbulletin 5.0.5
Vbulletin Vbulletin 5.0.0
Vbulletin Vbulletin 5.0.2
Vbulletin Vbulletin 5.0.1
1 EDB exploit
NA
CVE-2014-2022
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and previous versions allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.
Vbulletin Vbulletin
Vbulletin Vbulletin 4.2.1
Vbulletin Vbulletin 4.2.0
1 EDB exploit
9.8
CVSSv3
CVE-2016-6195
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin prior to 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote malicious users to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wi...
Vbulletin Vbulletin 4.2.3
Vbulletin Vbulletin
1 EDB exploit
2 Github repositories
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
client side
CVE-2023-31889
template injection
CVE-2024-4304
CVE-2006-4304
CVE-2024-33272
type confusion
CVE-2024-21345
CVE-2024-33271
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started