Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vbulletin vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-25135
vBulletin prior to 5.6.9 PL1 allows an unauthenticated remote malicious user to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for er...
Vbulletin Vbulletin 5.6.8
Vbulletin Vbulletin 5.6.9
Vbulletin Vbulletin 5.6.7
2 Github repositories
NA
CVE-2012-4328
Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 up to and including 4.1.12, Forum 4.1.2 up to and including 4.1.12, and the MAPI plugin 1.4.3 for vBulletin 3.x has unknown impact and attack vectors.
Vbulletin Mapi 1.4.3
Vbulletin Vbulletin Forum 4.1.2
Vbulletin Vbulletin Forum 4.1.12
Vbulletin Vbulletin Suite 4.1.2
Vbulletin Vbulletin Suite 4.1.12
NA
CVE-2005-3019
Multiple SQL injection vulnerabilities in vBulletin prior to 3.0.9 allow remote malicious users to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 2.0 Rc2
Jelsoft Vbulletin 3.0.4
Jelsoft Vbulletin 3.0 Beta 6
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 2.3.2
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 2.0 Rc3
Jelsoft Vbulletin 3.0.6
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.7
Jelsoft Vbulletin 2.0.3
Jelsoft Vbulletin 3.0 Beta 7
Jelsoft Vbulletin 3.0 Beta 3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.5
Jelsoft Vbulletin 2.2.6
Jelsoft Vbulletin 3.0.2
Jelsoft Vbulletin 3.0 Gamma
Jelsoft Vbulletin 2.2.9
4 EDB exploits
NA
CVE-2005-4621
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote malicious users to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extensio...
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 2.0 Rc2
Jelsoft Vbulletin 3.0.4
Jelsoft Vbulletin 3.0 Beta 6
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 2.3.8
Jelsoft Vbulletin 2.3.2
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 3.5.1
Jelsoft Vbulletin 2.0 Rc3
Jelsoft Vbulletin 3.0.6
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.7
Jelsoft Vbulletin 2.0.3
Jelsoft Vbulletin 3.0 Beta 7
Jelsoft Vbulletin 3.0.9
Jelsoft Vbulletin 3.0 Beta 3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.5
Jelsoft Vbulletin 2.2.6
NA
CVE-2005-0511
misc.php for vBulletin 3.0.6 and previous versions, when "Add Template Name in HTML Comments" is enabled, allows remote malicious users to execute arbitrary PHP code via nested variables in the template parameter.
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 3.0.4
Jelsoft Vbulletin 3.0.0 Rc4
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 2.2.9 Can
Jelsoft Vbulletin 3.0.0 Beta 2
Jelsoft Vbulletin 3.0.6
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.0.2
Jelsoft Vbulletin 2.0
Jelsoft Vbulletin 2.0.1
Jelsoft Vbulletin 2.2.7
Jelsoft Vbulletin 3.0.0 Can4
Jelsoft Vbulletin 2.0 Beta 2
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.5
Jelsoft Vbulletin 2.0 Beta 3
Jelsoft Vbulletin 3.0.0
Jelsoft Vbulletin 2.2.6
2 EDB exploits
NA
CVE-2005-3025
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4)...
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 2.0 Rc2
Jelsoft Vbulletin 3.0.4
Jelsoft Vbulletin 3.0 Beta 6
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 2.3.2
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 2.0 Rc3
Jelsoft Vbulletin 3.0.6
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.7
Jelsoft Vbulletin 2.0.3
Jelsoft Vbulletin 3.0 Beta 7
Jelsoft Vbulletin 3.0 Beta 3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.5
Jelsoft Vbulletin 2.2.6
Jelsoft Vbulletin 3.0.2
Jelsoft Vbulletin 3.0 Gamma
Jelsoft Vbulletin 2.2.9
NA
CVE-2005-3024
Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid para...
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 2.0 Rc2
Jelsoft Vbulletin 3.0.4
Jelsoft Vbulletin 3.0 Beta 6
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 2.3.2
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 2.0 Rc3
Jelsoft Vbulletin 3.0.6
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.7
Jelsoft Vbulletin 2.0.3
Jelsoft Vbulletin 3.0 Beta 7
Jelsoft Vbulletin 3.0 Beta 3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.5
Jelsoft Vbulletin 2.2.6
Jelsoft Vbulletin 3.0.2
Jelsoft Vbulletin 3.0 Gamma
Jelsoft Vbulletin 2.2.9
NA
CVE-2005-3022
Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4...
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 2.0 Rc2
Jelsoft Vbulletin 3.0.4
Jelsoft Vbulletin 3.0 Beta 6
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 2.3.2
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 2.0 Rc3
Jelsoft Vbulletin 3.0.6
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.7
Jelsoft Vbulletin 2.0.3
Jelsoft Vbulletin 3.0 Beta 7
Jelsoft Vbulletin 3.0.9
Jelsoft Vbulletin 3.0 Beta 3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.5
Jelsoft Vbulletin 2.2.6
Jelsoft Vbulletin 3.0.2
Jelsoft Vbulletin 3.0 Gamma
NA
CVE-2005-3020
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin prior to 3.0.9 allow remote malicious users to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to ...
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 2.0 Rc2
Jelsoft Vbulletin 3.0.4
Jelsoft Vbulletin 3.0 Beta 6
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 2.3.2
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 2.0 Rc3
Jelsoft Vbulletin 3.0.6
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.7
Jelsoft Vbulletin 2.0.3
Jelsoft Vbulletin 3.0 Beta 7
Jelsoft Vbulletin 3.0.9
Jelsoft Vbulletin 3.0 Beta 3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.5
Jelsoft Vbulletin 2.2.6
Jelsoft Vbulletin 3.0.2
Jelsoft Vbulletin 3.0 Gamma
6 EDB exploits
NA
CVE-2005-3023
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and previous versions allow remote malicious users to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php,...
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 2.0 Rc2
Jelsoft Vbulletin 3.0.4
Jelsoft Vbulletin 3.0 Beta 6
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 2.3.2
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 2.0 Rc3
Jelsoft Vbulletin 3.0.6
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.7
Jelsoft Vbulletin 2.0.3
Jelsoft Vbulletin 3.0 Beta 7
Jelsoft Vbulletin 3.0.9
Jelsoft Vbulletin 3.0 Beta 3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 3.0 Beta 2
Jelsoft Vbulletin 2.2.2
Jelsoft Vbulletin 2.2.5
Jelsoft Vbulletin 2.2.6
Jelsoft Vbulletin 3.0.2
Jelsoft Vbulletin 3.0 Gamma
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »