Known vulnerabilities in vBulletin 4.2.2 Patch Level 3

Vendor: vBulletin
Software: vBulletin
Version: 4.2.2 Patch Level 3
Software CPE: cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*
Total vulnerabilities: 4
Public exploits: 2
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting vBulletin version 4.2.2 Patch Level 3 vBulletin 4.2.2 Patch Level 3 is affected by 4 vulnerabilities: 2 critical, 1 high, 1 low Critical High Medium Low

Vulnerabilities (4)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU10311 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-6200
CWE-601 Low
No
No
- 26.01.2018 SB2018012904
#VU5836 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2016-6195
CWE-89 Critical
Public exploit available
No
- 16.02.2017 SB2016061502
#VU300 - Server-Side Request Forgery (SSRF)
CVE-2016-6483
CWE-918 Critical
Public exploit available
Exploited
- 10.08.2016 SB2016081009
#VU158 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89 High
No
Exploited
- 18.07.2016 SB2016061701