85 exploited vulnerabilities in Vbulletin
- Vendors
- Php, Vbulletin, Vbulletin Solutions, Apache, Vbseo, Tapatalk
- With known exploits
- 85
- Affected Vbulletin versions
- β€ 5.7.5, 6.0.3, 5.6.7, 5.6.8, 5.6.9, 5.6.2, 5.5.6, 5.6.0, 5.6.1.-, 5.5.4, 5.3.3, 5.0.0, 4.2.2, 4.2.3, 3.8.7, 3.8.8, 3.8.9, 5.2.0, 5.2.1, 5.2.2, 4.1, 4.1.10, 3.7.0, 4.2.0, 4.2.1
- Affected Vbseo versions
- All versions
- Affected Tapatalk versions
- = 1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.1.1, 1.1.2, 1.2.0, 1.2.1, 1.2.3, 1.2.6, 2.0, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.2.0, 3.9.0, 3.9.1, 3.9.2, 3.9.3, 4.0.0, 4.1.0, 4.2.0, 4.2.1, 4.3.0, 4.3.1, 4.4.0, 4.5.0, 4.5.1, 4.5.2, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 4.8.0, 4.8.1, 4.9.0, 5.0.0, 5.0.1, 5.1.0
- Affected Michael Brandon Vbgsitemap versions
- = 2.41
- Affected Jelsoft Vbulletin versions
- β€ 3.5.8, 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.6.4, 3.6.5, 2.3.0, 2.3.2, 2.3.3, 2.3.4, 2.3.8, 3.0, 3.0.0, 3.0.0_beta_2, 3.0.0_can4, 3.0.0_rc4, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.12, 3.0_beta_2, 1.0.1, 2.0.3, 2.0_rc2, 2.0_rc3, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2.8, 2.2.9, 3.0.7, 3.0_beta_3, 3.0_beta_4, 3.0_beta_5, 3.0_beta_6, 3.0_beta_7, 3.0_gamma, 3.0.8, 3.0.9, 2.0, 2.0.1, 2.0.2, 2.0_beta_2, 2.0_beta_3, 2.2.9_can, 2.1.9, 3.5.1, 3.5.2, 3.5.4
- Affected Mkportal versions
- = 1.1
Vulnerabilities with exploits
Highest CVSS first β 32 of these already have exploit code on Sploitus
CVE-2025-48827 3 exploits
π vBulletin 6.0.3 replaceAdTemplate Expression InjectionExploit for Improper Protection of Alternate Path in Vbulletin
CVE-2023-25135
CVE-2020-17496 1 exploit
CVE-2026-61511 8 exploits
CVE-2020-7373 2 exploits
CVE-2020-12720 12 exploits
vBulletin 5.6.1 SQL InjectionvBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection
CVE-2019-17132 4 exploits
vBulletin 5.0 < 5.5.4 - (updateAvatar) Authenticated Remote Code Execution ExploitvBulletin 5.0 5.5.4 - updateAvatar Authenticated Remote Code Execution
CVE-2019-16759 27 exploits
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_PlatformExploit for Code Injection in Vbulletin
CVE-2017-17672 5 exploits
vBulletin 5 cacheTemplates Unauthenticated Remote Arbitrary File Deletion VulnerabilityvBulletin cacheTemplates Unauthenticated Remote Arbitrary File Deletion(CVE-2017-17672)
CVE-2017-17671 1 exploit
CVE-2016-6195 7 exploits
CVE-2007-4120
CVE-2025-48828 1 exploit
CVE-2014-9463 3 exploits
vBSEO 3.6.0 functions_vbseo_hook.php Referer RCEvBulletin 4.x.x visitormessage.php Remote Code Injection Vulnerability
CVE-2016-6483 5 exploits
vBulletin 5.2.2 - Unauthenticated Server Side Request ForgeryvBulletin 5.2.2 - Server-Side Request Forgery
CVE-2014-2023 6 exploits
CVE-2014-5102
CVE-2013-6129 7 exploits
CVE-2012-4686 1 exploit
CVE-2008-2460
CVE-2007-2941 1 exploit
CVE-2007-1292 1 exploit
CVE-2006-5104 1 exploit
CVE-2006-4271
CVE-2006-2067 1 exploit
CVE-2006-2018
CVE-2005-3024
CVE-2005-3022
CVE-2005-3019 4 exploits
vBulletin 1.0.1 lite/2.x/3.0 - 'joinrequests.php?request' SQL InjectionvBulletin 1.0.1 lite/2.x/3.0 - '/admincp/user.php' Multiple SQL Injections
CVE-2005-0511 4 exploits
vBulletin - 'misc.php' Template Name Arbitrary Code Execution (Metasploit)vBulletin misc.php Template Name Arbitrary Code Execution
CVE-2004-1515 1 exploit
CVE-2002-1660 1 exploit
CVE-2001-0475
CVE-2014-2022 3 exploits
CVE-2014-9438
CVE-2010-1077 1 exploit
CVE-2006-6779 1 exploit
CVE-2006-6040 1 exploit
CVE-2006-4273 1 exploit
CVE-2003-0295 1 exploit
CVE-2013-3522 9 exploits
CVE-2008-6256
CVE-2007-3687 1 exploit
CVE-2006-2335
CVE-2018-6200
CVE-2007-1573
CVE-2014-8670
CVE-2025-46171
CVE-2023-39777
CVE-2007-2912