Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vbulletin

First CVE: May 27, 2008Active for: 18 yearsTotal CVEs: 54
59.1
VTI Score
TOP TARGET

Vbulletin is a forum and community-platform vendor with a narrowly focused but well-established product line, where its forum software and bundled extensions such as MAPI and VBGoogleMap have sustained long deployments across the internet. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a strong tendency to acquire public exploit code. The exposure recurs through application-layer injection and validation weaknesses—including cross-site scripting, SQL injection, code injection, and deserialization flaws—that are characteristic of web applications handling user input and dynamic content generation. Defenders should monitor this vendor's advisories closely given the historical pattern of public weaponization and the prevalence of legacy installations that may lag behind patching cycles. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
54
Total CVEs
More Total CVEs than 99% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
3.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Vbulletin over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 27, 2008
18 years ago
Most Recent CVE
Jul 23, 2025
366 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (54 CVEs).

54 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-16759CRITICAL
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Sep 24, 20199.899YESYES
CVE-2020-17496CRITICAL
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists becaus
Aug 12, 20209.898YESYES
CVE-2025-48827CRITICAL
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by
May 27, 20259.887NOYES
CVE-2020-12720CRITICAL
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
May 8, 20209.886NOYES
CVE-2016-6195CRITICAL
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitra
Aug 30, 20169.884NOYES
CVE-2025-48828HIGH
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative
May 27, 20258.179NOYES
CVE-2015-7808HIGH
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code vi
Nov 24, 20157.579NOYES
CVE-2013-6129HIGH
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], a
Oct 19, 20137.565NOYES
CVE-2020-7373CRITICAL
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists becaus
Oct 30, 20209.856NONO
CVE-2023-25135CRITICAL
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_
Feb 3, 20239.854NOYES
View all 54 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products54 CVEs
57%
22%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (61.1%)
Unknown21 (38.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (59.3%)
High1 (1.9%)
Unknown21 (38.9%)
User Interaction
None17 (31.5%)
Unknown21 (38.9%)
Required16 (29.6%)
Privileges Required
Low3 (5.6%)
High11 (20.4%)
None19 (35.2%)
Unknown21 (38.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (54 CVEs).

CISA KEV
2 CVEs
3.7% of CVEs· 99th percentile
Metasploit
8 CVEs
14.8% of CVEs· 99th percentile
Nuclei
8 CVEs
14.8% of CVEs· 97th percentile
ExploitDB
17 CVEs
31.5% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vbulletin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vbulletin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vbulletin's Products

View all 2 CNAs →

Top CWEs