Known vulnerabilities in vBulletin

Vendor: vBulletin
Software: vBulletin
Software CPE: cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*
Total vulnerabilities: 43
Public exploits: 15
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting vBulletin vBulletin is affected by 43 known vulnerabilities: 5 critical, 9 high, 9 medium, 20 low Critical High Medium Low

Vulnerabilities (43)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU110022 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-48828
CWE-94 Critical
Available
Exploited
5.7.5 Patch Level 3, 6.0.1 Patch Level 1, 6.0.2 Patch Level 1, 6.0.3 Patch Level 1 02.06.2025 SB2025052717
#VU109837 - Improper Protection of Alternate Path
CVE-2025-48827
CWE-424 Critical
Available
Exploited
5.7.5 Patch Level 3, 6.0.1 Patch Level 1, 6.0.2 Patch Level 1, 6.0.3 Patch Level 1 27.05.2025 SB2025052717
#VU80953 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-39777
CWE-79 Low
No
No
- 21.09.2023 SB2023092122
#VU49028 - Command injection
CVE-2020-7373
CWE-77 High
No
No
5.6.3 30.10.2020 SB2020103046
#VU46265 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25121
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU46266 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25117
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU46267 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25116
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU46268 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25115
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU46269 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25118
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU46270 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25119
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU46271 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25120
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU46272 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25123
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU46273 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25122
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU46274 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-25124
CWE-79 Low
No
No
- 03.09.2020 SB2020090605
#VU42751 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-17496
CWE-94 High
Available
Exploited
- 11.08.2020 SB2020081101
#VU27705 - Improper Access Control
CVE-2020-12720
CWE-284 Medium
Available
No
5.5.6 Patch Level 1, 5.6.0 Patch Level 1, 5.6.1 Patch Level 1 12.05.2020 SB2020051211
#VU21601 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-17271
CWE-89 Low
No
No
5.5.2 Patch Level 2, 5.5.3 Patch Level 2, 5.5.4 Patch Level 2 08.10.2019 SB2019100801
#VU21600 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-17132
CWE-94 High
Available
No
5.5.2 Patch Level 2, 5.5.3 Patch Level 2, 5.5.4 Patch Level 2 08.10.2019 SB2019100801
#VU30733 - Improper Restriction of Rendered UI Layers or Frames
CVE-2019-17131
CWE-1021 Low
No
No
5.5.4 04.10.2019 SB2019100408
#VU21323 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-16759
CWE-78 High
Available
Exploited
5.5.2 Patch Level 1, 5.5.3 Patch Level 1, 5.5.4 Patch Level 1 25.09.2019 SB2019092426


Showing elements 1 - 20 out of 43