vbulletin kayıtları
vbulletin üreticisine ait 54 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %3,7
- Silahlaştırılmış
- 8 · %14,8
- Pre-auth RCE
- 13
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 610 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-20 Improper Input Validation4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-502 Deserialization of Untrusted Data2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
54 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2019-16759Silahlaştırılmış | vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring revbulletin · vbulletin · CWE-94 | Kritik9,8 | KEV | %99,7 | 24 Eyl 2019 |
95Hemen | CVE-2020-17496Silahlaştırılmış | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panelvbulletin · vbulletin · CWE-74 | Kritik9,8 | KEV | %87,4 | 12 Ağu 2020 |
66Bu hafta | CVE-2020-12720Silahlaştırılmış | vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.vbulletin · vbulletin · CWE-89 | Kritik9,8 | — | %88,9 | 7 May 2020 |
62Bu hafta | CVE-2025-48827Silahlaştırılmış | vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when runningvbulletin · vbulletin · CWE-424 | Kritik9,8 | — | %75,8 | 27 May 2025 |
60Bu hafta | CVE-2016-6195Kavram kanıtı | SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 alvbulletin · vbulletin · CWE-89 | Kritik9,8 | — | %68,5 | 30 Ağu 2016 |
54Planlayın | CVE-2015-7808Silahlaştırılmış | The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection avbulletin · vbulletin · CWE-20 | Yüksek7,5 | — | %80,6 | 24 Kas 2015 |
53Planlayın | CVE-2020-7373İstismar yok | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panelvbulletin · vbulletin · CWE-94 | Kritik9,8 | — | %45,0 | 30 Eki 2020 |
49Planlayın | CVE-2025-48828Silahlaştırılmış | Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.vbulletin · vbulletin · CWE-424 | Yüksek8,1 | — | %57,6 | 27 May 2025 |
46Planlayın | CVE-2013-6129Silahlaştırılmış | The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldatavbulletin · vbulletin · CWE-264 | Yüksek7,5 | — | %51,9 | 19 Eki 2013 |
46Planlayın | CVE-2023-25135Kavram kanıtı | vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers desevbulletin · vbulletin · CWE-502 | Kritik9,8 | — | %23,9 | 3 Şub 2023 |
44Planlayın | CVE-2017-17672Kavram kanıtı | In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certavbulletin · vbulletin · CWE-502 | Kritik9,8 | — | %15,2 | 13 Ara 2017 |
43Planlayın | CVE-2019-17132Kavram kanıtı | vBulletin through 5.5.4 mishandles custom avatars.vbulletin · vbulletin · CWE-20 | Kritik9,8 | — | %11,7 | 4 Eki 2019 |
41Planlayın | CVE-2012-4328İstismar yok | Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 through 4.1.12, Forum 4.1.2 through 4.1.12, and the MAPI plugin 1.4.3 for vBuvbulletin · mapi | Kritik10,0 | — | %2,5 | 14 Ağu 2012 |
40Planlayın | CVE-2017-17671İstismar yok | vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated requestvbulletin · vbulletin · CWE-22 | Kritik9,8 | — | %3,1 | 13 Ara 2017 |
39İzleyin | CVE-2014-9463Kavram kanıtı | functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer vbseo · vbseo · CWE-94 | Yüksek8,8 | — | %14,8 | 15 Eyl 2017 |
38İzleyin | CVE-2016-6483Kavram kanıtı | The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.vbulletin · vbulletin · CWE-918 | Yüksek8,6 | — | %11,9 | 1 Eyl 2016 |
34İzleyin | CVE-2013-3522Silahlaştırılmış | SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authevbulletin · vbulletin · CWE-89 | Orta6,5 | — | %27,1 | 10 May 2013 |
34İzleyin | CVE-2017-7569İstismar yok | In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHvbulletin · vbulletin · CWE-918 | Yüksek8,6 | — | %1,2 | 6 Nis 2017 |
30İzleyin | CVE-2014-5102İstismar yok | SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the critevbulletin · vbulletin · CWE-89 | Yüksek7,5 | — | %1,4 | 25 Tem 2014 |
30İzleyin | CVE-2008-2460İstismar yok | SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parametervbulletin · vbulletin · CWE-89 | Yüksek7,5 | — | %1,1 | 27 May 2008 |
30İzleyin | CVE-2012-4686Kavram kanıtı | SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announvbulletin · vbulletin · CWE-89 | Yüksek7,5 | — | %1,1 | 28 Ağu 2012 |
30İzleyin | CVE-2008-4706Kavram kanıtı | SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commavbulletin · vbgooglemap · CWE-89 | Yüksek7,5 | — | %1,0 | 23 Eki 2008 |
29İzleyin | CVE-2014-2022Kavram kanıtı | SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authentvbulletin · vbulletin · CWE-89 | Yüksek7,1 | — | %2,7 | 15 Eki 2014 |
28İzleyin | CVE-2010-1077Kavram kanıtı | Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execuvbseo · vbseo · CWE-22 | Orta6,8 | — | %1,9 | 23 Mar 2010 |
27İzleyin | CVE-2014-9438İstismar yok | Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the authvbulletin · vbulletin · CWE-352 | Orta6,8 | — | %1,1 | 2 Oca 2015 |
- CVE-2019-1675999Hemen
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100vbulletin · vbulletin24 Eyl 2019
- CVE-2020-1749695Hemen
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87vbulletin · vbulletin12 Ağu 2020
- CVE-2020-1272066Bu hafta
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
KritikCVSS 9,8SilahlaştırılmışEPSS %89vbulletin · vbulletin7 May 2020
- CVE-2025-4882762Bu hafta
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running
KritikCVSS 9,8SilahlaştırılmışEPSS %76vbulletin · vbulletin27 May 2025
- CVE-2016-619560Bu hafta
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 al
KritikCVSS 9,8Kavram kanıtıEPSS %68vbulletin · vbulletin30 Ağu 2016
- CVE-2015-780854Planlayın
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection a
YüksekCVSS 7,5SilahlaştırılmışEPSS %81vbulletin · vbulletin24 Kas 2015
- CVE-2020-737353Planlayın
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel
KritikCVSS 9,8İstismar yokEPSS %45vbulletin · vbulletin30 Eki 2020
- CVE-2025-4882849Planlayın
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.
YüksekCVSS 8,1SilahlaştırılmışEPSS %58vbulletin · vbulletin27 May 2025
- CVE-2013-612946Planlayın
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata
YüksekCVSS 7,5SilahlaştırılmışEPSS %52vbulletin · vbulletin19 Eki 2013
- CVE-2023-2513546Planlayın
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers dese
KritikCVSS 9,8Kavram kanıtıEPSS %24vbulletin · vbulletin3 Şub 2023
- CVE-2017-1767244Planlayın
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certa
KritikCVSS 9,8Kavram kanıtıEPSS %15vbulletin · vbulletin13 Ara 2017
- CVE-2019-1713243Planlayın
vBulletin through 5.5.4 mishandles custom avatars.
KritikCVSS 9,8Kavram kanıtıEPSS %12vbulletin · vbulletin4 Eki 2019
- CVE-2012-432841Planlayın
Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 through 4.1.12, Forum 4.1.2 through 4.1.12, and the MAPI plugin 1.4.3 for vBu
KritikCVSS 10,0İstismar yokEPSS %2vbulletin · mapi14 Ağu 2012
- CVE-2017-1767140Planlayın
vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request
KritikCVSS 9,8İstismar yokEPSS %3vbulletin · vbulletin13 Ara 2017
- CVE-2014-946339İzleyin
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer
YüksekCVSS 8,8Kavram kanıtıEPSS %15vbseo · vbseo15 Eyl 2017
- CVE-2016-648338İzleyin
The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.
YüksekCVSS 8,6Kavram kanıtıEPSS %12vbulletin · vbulletin1 Eyl 2016
- CVE-2013-352234İzleyin
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authe
OrtaCVSS 6,5SilahlaştırılmışEPSS %27vbulletin · vbulletin10 May 2013
- CVE-2017-756934İzleyin
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PH
YüksekCVSS 8,6İstismar yokEPSS %1vbulletin · vbulletin6 Nis 2017
- CVE-2014-510230İzleyin
SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the crite
YüksekCVSS 7,5İstismar yokEPSS %1vbulletin · vbulletin25 Tem 2014
- CVE-2008-246030İzleyin
SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter
YüksekCVSS 7,5İstismar yokEPSS %1vbulletin · vbulletin27 May 2008
- CVE-2012-468630İzleyin
SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announ
YüksekCVSS 7,5Kavram kanıtıEPSS %1vbulletin · vbulletin28 Ağu 2012
- CVE-2008-470630İzleyin
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL comma
YüksekCVSS 7,5Kavram kanıtıEPSS %1vbulletin · vbgooglemap23 Eki 2008
- CVE-2014-202229İzleyin
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authent
YüksekCVSS 7,1Kavram kanıtıEPSS %3vbulletin · vbulletin15 Eki 2014
- CVE-2010-107728İzleyin
Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execu
OrtaCVSS 6,8Kavram kanıtıEPSS %2vbseo · vbseo23 Mar 2010
- CVE-2014-943827İzleyin
Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the auth
OrtaCVSS 6,8İstismar yokEPSS %1vbulletin · vbulletin2 Oca 2015