Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vbulletin vbulletin vulnerabilities and exploits
(subscribe to this query)
435
VMScore
CVE-2008-2744
Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10 and 3.7.1 allows remote malicious users to inject arbitrary web script or HTML via unknown vectors and an "obscure method." NOTE: the vector is probably in the redirect parameter to the Admin Control Panel (ad...
Vbulletin Vbulletin 3.7.1
Vbulletin Vbulletin 3.6.10
1 EDB exploit
755
VMScore
CVE-2013-6129
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote malicious users to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013.
Vbulletin Vbulletin 4.1
Vbulletin Vbulletin 5.0.0
1 EDB exploit
1 Github repository
685
VMScore
CVE-2006-6779
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote malicious users to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript.
Jelsoft Vbulletin 3.5.4
Jelsoft Vbulletin 3.6.0
Jelsoft Vbulletin 3.6.3
Jelsoft Vbulletin 3.6.4
Jelsoft Vbulletin 3.5.1
Jelsoft Vbulletin 3.5.2
Jelsoft Vbulletin 3.6.1
Jelsoft Vbulletin 3.6.2
1 EDB exploit
755
VMScore
CVE-2007-1292
SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin prior to 3.5.8, and prior to 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter. NOTE: the vendor states that the attack is feasible only i...
Jelsoft Vbulletin 3.6.0
Jelsoft Vbulletin 3.6.5
Jelsoft Vbulletin
Jelsoft Vbulletin 3.6.1
Jelsoft Vbulletin 3.6.2
Jelsoft Vbulletin 3.6.3
Jelsoft Vbulletin 3.6.4
1 EDB exploit
383
VMScore
CVE-2002-1678
Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft vBulletin 2.0 rc 2 up to and including 2.2.4 allows remote malicious users to steal authentication credentials by injecting script into $letterbits.
Jelsoft Vbulletin 2.0 Rc3
Jelsoft Vbulletin 2.2.0
Jelsoft Vbulletin 2.2.3
Jelsoft Vbulletin 2.2.4
Jelsoft Vbulletin 2.0 Rc2
Jelsoft Vbulletin 2.2.1
Jelsoft Vbulletin 2.2.2
668
VMScore
CVE-2004-2695
SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 up to and including 3.0.3 allows remote malicious users to execute arbitrary SQL statements via the x_invoice_num parameter. NOTE: this issue might be related to ...
Jelsoft Vbulletin 3.0.3
Jelsoft Vbulletin 3.0 Beta 2
Point-to-point Protocol Project Point-to-point Protocol 2.4.1
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 3.0.2
Jelsoft Vbulletin 3.0 Beta 7
Jelsoft Vbulletin 3.0 Gamma
Jelsoft Vbulletin 3.0 Beta 3
Jelsoft Vbulletin 3.0 Beta 4
Jelsoft Vbulletin 3.0
Jelsoft Vbulletin 3.0 Beta 5
Jelsoft Vbulletin 3.0 Beta 6
890
VMScore
CVE-2012-4328
Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 up to and including 4.1.12, Forum 4.1.2 up to and including 4.1.12, and the MAPI plugin 1.4.3 for vBulletin 3.x has unknown impact and attack vectors.
Vbulletin Vbulletin Suite 4.1.2
Vbulletin Vbulletin Suite 4.1.12
Vbulletin Vbulletin Forum 4.1.12
Vbulletin Vbulletin Forum 4.1.2
Vbulletin Mapi 1.4.3
755
VMScore
CVE-2006-5104
SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote malicious users to execute arbitrary SQL commands via the templatesused parameter.
Jelsoft Vbulletin 2.3.8
Jelsoft Vbulletin 2.3.0
Jelsoft Vbulletin 2.3.2
Jelsoft Vbulletin 2.3.3
Jelsoft Vbulletin 2.3.4
1 EDB exploit
510
VMScore
CVE-2005-0429
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 up to and including 3.0.4, when showforumusers is enabled, allows remote malicious users to execute inject arbitrary PHP commands via the comma parameter.
Jelsoft Vbulletin 3.0
Jelsoft Vbulletin 3.0.1
Jelsoft Vbulletin 3.0.2
Jelsoft Vbulletin 3.0.3
Jelsoft Vbulletin 3.0.4
2 EDB exploits
685
VMScore
CVE-2006-6040
Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote malicious users to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a savenavprefs action.
Jelsoft Vbulletin 3.6.0
Jelsoft Vbulletin 3.6.1
Jelsoft Vbulletin 3.6.2
Jelsoft Vbulletin 3.6.3
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49333
CVE-2024-33901
CVE-2024-36001
CVE-2024-2835
firewall
XPath injection
authentication bypass
CVE-2024-22120
CVE-2024-32002
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »