Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jelsoft

First CVE: Jun 27, 2001Active for: 25 yearsTotal CVEs: 60
36.8
VTI Score
Medium

Jelsoft's vulnerability footprint centers on vBulletin, a widely deployed community forum platform, alongside a smaller portfolio of related web applications and administrative tools. Despite a narrow product range, the vendor occupies a prominent position in the vulnerability landscape because vBulletin's prevalence as an internet-facing discussion platform makes its flaws broadly visible and actionable; vulnerabilities affecting these products frequently acquire public exploit code. The exposure concentrates in application-layer input-handling weakness classes spanning cross-site scripting, SQL injection, OS command injection, and sensitive information exposure, reflecting the challenges of securing user-facing web applications with complex parsing and database interaction logic. Defenders should treat vBulletin patches as a priority for internet-facing instances and monitor for proof-of-concept activity following disclosure, since the platform's accessibility and user base attract rapid weaponization; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
60
Total CVEs
More Total CVEs than 99% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jelsoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Jun 23, 2009
6,240 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (60 CVEs).

60 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-0511HIGH
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the te
Feb 21, 20057.556NOYES
CVE-2004-1515HIGH
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstra
Dec 31, 20047.534NOYES
CVE-2002-1660HIGH
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
Dec 31, 20027.533NOYES
CVE-2005-3019HIGH
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) lim
Sep 21, 20057.529NOYES
CVE-2007-3196HIGH
SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a sh
Jun 12, 20077.528NOYES
CVE-2007-1292HIGH
SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQ
Mar 7, 20077.528NOYES
CVE-2006-5104HIGH
SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter.
Oct 3, 20067.528NOYES
CVE-2006-2018HIGH
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has
Apr 25, 20067.528NONO
CVE-2006-6779MEDIUM
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execu
Dec 28, 20066.827NOYES
CVE-2006-6040MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs
Nov 22, 20066.827NOYES
View all 60 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products60 CVEs
8%
62%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown60 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown60 (100.0%)
User Interaction
None0 (0.0%)
Unknown60 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown60 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (60 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
27 CVEs
45.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jelsoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jelsoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jelsoft's Products

View all 1 CNAs →

Top CWEs