Dragonbyte Tech develops a focused suite of forum extensions and security modules for vBulletin communities, a niche but persistent application ecosystem. The vendor's vulnerability footprint, though modest in scope, spans multiple add-on products including its RPG module, activity tracking, downloads, and security components that extend a widely used discussion platform. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dragonbyte Tech over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6667MEDIUM Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via t | Jan 11, 2018 | 6.1 | 31 | NO | YES |
CVE-2012-6682MEDIUM Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attac | Jan 11, 2018 | 6.1 | 21 | NO | NO |
CVE-2012-6671MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG module before 1.0.8 for vBulletin when creating a new monster, al | Jan 11, 2018 | 6.1 | 21 | NO | NO |
CVE-2012-6670MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vBulletin allow remote attackers to inject arbitrary web scrip | Jan 11, 2018 | 6.1 | 21 | NO | NO |
CVE-2012-6668MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module before 6.0.6 for vBulletin allow remote attackers to inject a | Jan 11, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-12580MEDIUM library/DBTech/Security/Action/Sessions.php in DragonByte vBSecurity 3.x through 3.3.0 for vBulletin 3 and vBulletin 4 allows self-XSS via $session['user_agent'] in the "Login Sess | Jun 19, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dragonbyte Tech.
Media articles that mention a CVE ID that affects a product developed by Dragonbyte Tech — matched by CVE ID, not by vendor name.