Jelsoft's vulnerability footprint centers on vBulletin, a widely deployed community forum platform, alongside a smaller portfolio of related web applications and administrative tools. Despite a narrow product range, the vendor occupies a prominent position in the vulnerability landscape because vBulletin's prevalence as an internet-facing discussion platform makes its flaws broadly visible and actionable; vulnerabilities affecting these products frequently acquire public exploit code. The exposure concentrates in application-layer input-handling weakness classes spanning cross-site scripting, SQL injection, OS command injection, and sensitive information exposure, reflecting the challenges of securing user-facing web applications with complex parsing and database interaction logic. Defenders should treat vBulletin patches as a priority for internet-facing instances and monitor for proof-of-concept activity following disclosure, since the platform's accessibility and user base attract rapid weaponization; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jelsoft over time
Signals from CVEs in this vendor scope (60 CVEs).
60 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-0511HIGH misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the te | Feb 21, 2005 | 7.5 | 56 | NO | YES |
CVE-2004-1515HIGH SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstra | Dec 31, 2004 | 7.5 | 34 | NO | YES |
CVE-2002-1660HIGH calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter. | Dec 31, 2002 | 7.5 | 33 | NO | YES |
CVE-2005-3019HIGH Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) lim | Sep 21, 2005 | 7.5 | 29 | NO | YES |
CVE-2007-3196HIGH SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a sh | Jun 12, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-1292HIGH SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQ | Mar 7, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-5104HIGH SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter. | Oct 3, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-2018HIGH SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has | Apr 25, 2006 | 7.5 | 28 | NO | NO |
CVE-2006-6779MEDIUM Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execu | Dec 28, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-6040MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs | Nov 22, 2006 | 6.8 | 27 | NO | YES |
Signals from CVEs in this vendor scope (60 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jelsoft.
Media articles that mention a CVE ID that affects a product developed by Jelsoft — matched by CVE ID, not by vendor name.