Vbseo is a search-engine optimization plugin for forum software that presents a narrow but specialized attack surface centered on web-application input handling. Its observed vulnerability profile clusters around code injection, path traversal, and cross-site scripting weaknesses, which are characteristic of template and user-input processing in web-facing plugins. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vbseo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9463HIGH functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php. | Sep 15, 2017 | 8.8 | 40 | NO | YES |
CVE-2010-1077MEDIUM Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitrary local files via directory t | Mar 23, 2010 | 6.8 | 27 | NO | YES |
CVE-2012-6666MEDIUM vBSeo before 3.6.0PL2 allows XSS via the member.php u parameter. | Feb 10, 2020 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vbseo.
Media articles that mention a CVE ID that affects a product developed by Vbseo — matched by CVE ID, not by vendor name.