vBulletin Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for vBulletin products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

8

In CISA KEV

2

Beyond CISA KEV

6

Sensor Observed

1

Virtual Patch Available

0

vBulletin KEVs Added by Year

Loading...

8 vBulletin KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-48828

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting...

Confirmed Not in CISA 27 May 2025
CVE-2025-48827

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP...

High Not in CISA 03 Jun 2026
CVE-2023-25135

vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers...

High Not in CISA 07 Jul 2025
CVE-2020-12720

vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

High Not in CISA 25 Jun 2025
CVE-2016-6195

SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows...

High Not in CISA 30 Aug 2016
CVE-2013-6129

The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid,...

High Not in CISA 19 Oct 2013
CVE-2020-17496

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel...

Confirmed In CISA 03 Nov 2021
CVE-2019-16759

vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

Confirmed In CISA 03 Nov 2021

Common Vulnerability Classes (CWE)

  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
  • CWE-424 — Improper Protection of Alternate Path 2
  • CWE-264 — Permissions, Privileges, and Access Controls 1
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
  • CWE-502 — Deserialization of Untrusted Data 1
  • CWE-306 — Missing Authentication for Critical Function 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology