vBulletin Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for vBulletin products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
8
In CISA KEV
2
Beyond CISA KEV
6
Sensor Observed
1
Virtual Patch Available
0
vBulletin KEVs Added by Year
8 vBulletin KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-48828
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting... |
vBulletin | Confirmed | Not in CISA | 27 May 2025 |
|
CVE-2025-48827
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP... |
vBulletin | High | Not in CISA | 03 Jun 2026 |
|
CVE-2023-25135
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers... |
vBulletin | High | Not in CISA | 07 Jul 2025 |
|
CVE-2020-12720
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. |
vBulletin | High | Not in CISA | 25 Jun 2025 |
|
CVE-2016-6195
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows... |
vBulletin | High | Not in CISA | 30 Aug 2016 |
|
CVE-2013-6129
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid,... |
vBulletin | High | Not in CISA | 19 Oct 2013 |
|
CVE-2020-17496
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel... |
vBulletin | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. |
vBulletin | Confirmed | In CISA | 03 Nov 2021 |
Common Vulnerability Classes (CWE)
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
- CWE-424 — Improper Protection of Alternate Path 2
- CWE-264 — Permissions, Privileges, and Access Controls 1
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
- CWE-502 — Deserialization of Untrusted Data 1
- CWE-306 — Missing Authentication for Critical Function 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology