İçeriğe atla
Noroxi

vbulletin kayıtları

vbulletin üreticisine ait 54 yayımlanmış kayıt.

Tüm kayıtlar

54 kayıt
  • vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vbulletin · vbulletin24 Eyl 2019

  • vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87

    vbulletin · vbulletin12 Ağu 2020

  • CVE-2020-12720
    66Bu hafta

    vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

    KritikCVSS 9,8SilahlaştırılmışEPSS %89

    vbulletin · vbulletin7 May 2020

  • CVE-2025-48827
    62Bu hafta

    vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running

    KritikCVSS 9,8SilahlaştırılmışEPSS %76

    vbulletin · vbulletin27 May 2025

  • CVE-2016-6195
    60Bu hafta

    SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 al

    KritikCVSS 9,8Kavram kanıtıEPSS %68

    vbulletin · vbulletin30 Ağu 2016

  • CVE-2015-7808
    54Planlayın

    The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection a

    YüksekCVSS 7,5SilahlaştırılmışEPSS %81

    vbulletin · vbulletin24 Kas 2015

  • CVE-2020-7373
    53Planlayın

    vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel

    KritikCVSS 9,8İstismar yokEPSS %45

    vbulletin · vbulletin30 Eki 2020

  • CVE-2025-48828
    49Planlayın

    Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.

    YüksekCVSS 8,1SilahlaştırılmışEPSS %58

    vbulletin · vbulletin27 May 2025

  • CVE-2013-6129
    46Planlayın

    The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata

    YüksekCVSS 7,5SilahlaştırılmışEPSS %52

    vbulletin · vbulletin19 Eki 2013

  • CVE-2023-25135
    46Planlayın

    vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers dese

    KritikCVSS 9,8Kavram kanıtıEPSS %24

    vbulletin · vbulletin3 Şub 2023

  • CVE-2017-17672
    44Planlayın

    In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certa

    KritikCVSS 9,8Kavram kanıtıEPSS %15

    vbulletin · vbulletin13 Ara 2017

  • CVE-2019-17132
    43Planlayın

    vBulletin through 5.5.4 mishandles custom avatars.

    KritikCVSS 9,8Kavram kanıtıEPSS %12

    vbulletin · vbulletin4 Eki 2019

  • CVE-2012-4328
    41Planlayın

    Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 through 4.1.12, Forum 4.1.2 through 4.1.12, and the MAPI plugin 1.4.3 for vBu

    KritikCVSS 10,0İstismar yokEPSS %2

    vbulletin · mapi14 Ağu 2012

  • CVE-2017-17671
    40Planlayın

    vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request

    KritikCVSS 9,8İstismar yokEPSS %3

    vbulletin · vbulletin13 Ara 2017

  • CVE-2014-9463
    39İzleyin

    functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer

    YüksekCVSS 8,8Kavram kanıtıEPSS %15

    vbseo · vbseo15 Eyl 2017

  • CVE-2016-6483
    38İzleyin

    The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.

    YüksekCVSS 8,6Kavram kanıtıEPSS %12

    vbulletin · vbulletin1 Eyl 2016

  • CVE-2013-3522
    34İzleyin

    SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authe

    OrtaCVSS 6,5SilahlaştırılmışEPSS %27

    vbulletin · vbulletin10 May 2013

  • CVE-2017-7569
    34İzleyin

    In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PH

    YüksekCVSS 8,6İstismar yokEPSS %1

    vbulletin · vbulletin6 Nis 2017

  • CVE-2014-5102
    30İzleyin

    SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the crite

    YüksekCVSS 7,5İstismar yokEPSS %1

    vbulletin · vbulletin25 Tem 2014

  • CVE-2008-2460
    30İzleyin

    SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter

    YüksekCVSS 7,5İstismar yokEPSS %1

    vbulletin · vbulletin27 May 2008

  • CVE-2012-4686
    30İzleyin

    SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announ

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    vbulletin · vbulletin28 Ağu 2012

  • CVE-2008-4706
    30İzleyin

    SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL comma

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    vbulletin · vbgooglemap23 Eki 2008

  • CVE-2014-2022
    29İzleyin

    SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authent

    YüksekCVSS 7,1Kavram kanıtıEPSS %3

    vbulletin · vbulletin15 Eki 2014

  • CVE-2010-1077
    28İzleyin

    Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execu

    OrtaCVSS 6,8Kavram kanıtıEPSS %2

    vbseo · vbseo23 Mar 2010

  • CVE-2014-9438
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the auth

    OrtaCVSS 6,8İstismar yokEPSS %1

    vbulletin · vbulletin2 Oca 2015