Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vbulletin vbulletin 5.0.0 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2017-17671
vBulletin up to and including 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is blocked but ..\ t...
Vbulletin Vbulletin 5.0.0
Vbulletin Vbulletin
9.8
CVSSv3
CVE-2017-17672
In vBulletin up to and including 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplat...
Vbulletin Vbulletin
Vbulletin Vbulletin 5.0.0
1 EDB exploit
9.8
CVSSv3
CVE-2014-2023
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and previous versions and 5.x up to and including 5.2.1 for vBulletin allow remote malicious users to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscrib...
Tapatalk Tapatalk 5.1.2
Tapatalk Tapatalk 5.1.3
Tapatalk Tapatalk 5.2.0
Tapatalk Tapatalk 5.2.1
Tapatalk Tapatalk 3.9.2
Tapatalk Tapatalk 3.9.3
Tapatalk Tapatalk 4.0.0
Tapatalk Tapatalk 4.1.0
Tapatalk Tapatalk 1.2.3
Tapatalk Tapatalk 1.2.6
Tapatalk Tapatalk 2.0
Tapatalk Tapatalk 1.0.0
Tapatalk Tapatalk 1.0.1
Tapatalk Tapatalk 4.9.0
Tapatalk Tapatalk 4.8.1
Tapatalk Tapatalk 4.3.1
Tapatalk Tapatalk 4.5.0
Tapatalk Tapatalk 4.5.1
Tapatalk Tapatalk 4.6.0
Tapatalk Tapatalk 3.9.0
Tapatalk Tapatalk 3.9.1
Tapatalk Tapatalk 3.1.2
1 EDB exploit
6.5
CVSSv3
CVE-2015-3419
vBulletin 5.x up to and including 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vectors related to an input validation failure.
Vbulletin Vbulletin 5.0.1
Vbulletin Vbulletin 5.0.2
Vbulletin Vbulletin 5.0.3
Vbulletin Vbulletin 5.0.4
Vbulletin Vbulletin 5.1.6
Vbulletin Vbulletin 5.1.3
Vbulletin Vbulletin 5.0.0
Vbulletin Vbulletin 5.0.5
Vbulletin Vbulletin 5.1.0
Vbulletin Vbulletin 5.1.5
Vbulletin Vbulletin 5.1.4
Vbulletin Vbulletin 5.1.2
Vbulletin Vbulletin 5.1.1
NA
CVE-2015-7808
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 up to and including 5.1.9 allows remote malicious users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeAr...
Vbulletin Vbulletin 5.0.3
Vbulletin Vbulletin 5.0.4
Vbulletin Vbulletin 5.0.5
Vbulletin Vbulletin 5.1.0
Vbulletin Vbulletin 5.1.9
Vbulletin Vbulletin 5.0.0
Vbulletin Vbulletin 5.0.2
Vbulletin Vbulletin 5.1.2
Vbulletin Vbulletin 5.1.5
Vbulletin Vbulletin 5.1.7
Vbulletin Vbulletin 5.1.3
Vbulletin Vbulletin 5.1.4
Vbulletin Vbulletin 5.0.1
Vbulletin Vbulletin 5.1.1
Vbulletin Vbulletin 5.1.6
Vbulletin Vbulletin 5.1.8
2 EDB exploits
4 Github repositories
NA
CVE-2014-2021
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and previous versions, and 5.0.x up to and including 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client...
Vbulletin Vbulletin 5.0.4
Vbulletin Vbulletin 5.0.3
Vbulletin Vbulletin
Vbulletin Vbulletin 5.0.5
Vbulletin Vbulletin 5.0.0
Vbulletin Vbulletin 5.0.2
Vbulletin Vbulletin 5.0.1
1 EDB exploit
NA
CVE-2013-6129
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote malicious users to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013.
Vbulletin Vbulletin 4.1
Vbulletin Vbulletin 5.0.0
1 EDB exploit
1 Github repository
NA
CVE-2013-3522
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and previous versions allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.
Vbulletin Vbulletin 5.0.0
2 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started