Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vbulletin vbulletin vulnerabilities and exploits
(subscribe to this query)
905
VMScore
CVE-2014-9463
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php.
Vbseo Vbseo -
1 EDB exploit
890
VMScore
CVE-2012-4328
Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 up to and including 4.1.12, Forum 4.1.2 up to and including 4.1.12, and the MAPI plugin 1.4.3 for vBulletin 3.x has unknown impact and attack vectors.
Vbulletin Vbulletin Suite 4.1.2
Vbulletin Vbulletin Suite 4.1.12
Vbulletin Vbulletin Forum 4.1.12
Vbulletin Vbulletin Forum 4.1.2
Vbulletin Mapi 1.4.3
828
VMScore
CVE-2007-4120
Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote malicious users to execute arbitrary PHP code via a URL in the (1) classfile parameter to includes/functions.php, the (2) nextitem parameter to includes/functions_cron.php, and the (3) spec...
Jelsoft Vbulletin 3.6.5
800
VMScore
CVE-2019-16759
vBulletin 5.x up to and including 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Vbulletin Vbulletin
1 EDB exploit
1 Metasploit module
16 Github repositories
770
VMScore
CVE-2005-3019
Multiple SQL injection vulnerabilities in vBulletin prior to 3.0.9 allow remote malicious users to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
Jelsoft Vbulletin 1.0.1
Jelsoft Vbulletin 2.2.3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 2.3.2
Jelsoft Vbulletin 2.3.3
Jelsoft Vbulletin 3.0.6
Jelsoft Vbulletin 3.0.7
Jelsoft Vbulletin 3.0 Beta 7
Jelsoft Vbulletin 3.0 Gamma
Jelsoft Vbulletin 2.0.3
Jelsoft Vbulletin 2.0 Rc2
Jelsoft Vbulletin 2.2.5
Jelsoft Vbulletin 2.2.6
Jelsoft Vbulletin 2.3.4
Jelsoft Vbulletin 3.0
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 3.0.8
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.9
Jelsoft Vbulletin 2.3.0
4 EDB exploits
761
VMScore
CVE-2015-7808
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 up to and including 5.1.9 allows remote malicious users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeAr...
Vbulletin Vbulletin 5.0.3
Vbulletin Vbulletin 5.0.4
Vbulletin Vbulletin 5.0.5
Vbulletin Vbulletin 5.1.0
Vbulletin Vbulletin 5.1.9
Vbulletin Vbulletin 5.0.0
Vbulletin Vbulletin 5.0.2
Vbulletin Vbulletin 5.1.2
Vbulletin Vbulletin 5.1.5
Vbulletin Vbulletin 5.1.7
Vbulletin Vbulletin 5.1.3
Vbulletin Vbulletin 5.1.4
Vbulletin Vbulletin 5.0.1
Vbulletin Vbulletin 5.1.1
Vbulletin Vbulletin 5.1.6
Vbulletin Vbulletin 5.1.8
2 EDB exploits
4 Github repositories
760
VMScore
CVE-2005-0511
misc.php for vBulletin 3.0.6 and previous versions, when "Add Template Name in HTML Comments" is enabled, allows remote malicious users to execute arbitrary PHP code via nested variables in the template parameter.
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.9 Can
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 3.0.2
Jelsoft Vbulletin 2.0 Beta 2
Jelsoft Vbulletin 2.0 Beta 3
Jelsoft Vbulletin 2.2.7
Jelsoft Vbulletin 2.2.8
Jelsoft Vbulletin 3.0.0 Can4
Jelsoft Vbulletin 3.0.0 Rc4
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.0
Jelsoft Vbulletin 2.2.3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 2.3.3
Jelsoft Vbulletin 2.3.4
Jelsoft Vbulletin 3.0.3
Jelsoft Vbulletin 3.0.4
Jelsoft Vbulletin 2.0.1
2 EDB exploits
756
VMScore
CVE-2016-6195
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin prior to 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote malicious users to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wi...
Vbulletin Vbulletin 4.2.3
Vbulletin Vbulletin
1 EDB exploit
2 Github repositories
756
VMScore
CVE-2007-2911
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin prior to 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (GPC['search']['datelineafter'] variable), a related...
Jelsoft Vbulletin
755
VMScore
CVE-2017-17672
In vBulletin up to and including 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplat...
Vbulletin Vbulletin
Vbulletin Vbulletin 5.0.0
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »