Vbulletin is a forum and community-platform vendor with a narrowly focused but well-established product line, where its forum software and bundled extensions such as MAPI and VBGoogleMap have sustained long deployments across the internet. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a strong tendency to acquire public exploit code. The exposure recurs through application-layer injection and validation weaknesses—including cross-site scripting, SQL injection, code injection, and deserialization flaws—that are characteristic of web applications handling user input and dynamic content generation. Defenders should monitor this vendor's advisories closely given the historical pattern of public weaponization and the prevalence of legacy installations that may lag behind patching cycles. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vbulletin over time
Signals from CVEs in this vendor scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16759CRITICAL vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. | Sep 24, 2019 | 9.8 | 99 | YES | YES |
CVE-2020-17496CRITICAL vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists becaus | Aug 12, 2020 | 9.8 | 98 | YES | YES |
CVE-2025-48827CRITICAL vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by | May 27, 2025 | 9.8 | 87 | NO | YES |
CVE-2020-12720CRITICAL vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. | May 8, 2020 | 9.8 | 86 | NO | YES |
CVE-2016-6195CRITICAL SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitra | Aug 30, 2016 | 9.8 | 84 | NO | YES |
CVE-2025-48828HIGH Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative | May 27, 2025 | 8.1 | 79 | NO | YES |
CVE-2015-7808HIGH The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code vi | Nov 24, 2015 | 7.5 | 79 | NO | YES |
CVE-2013-6129HIGH The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], a | Oct 19, 2013 | 7.5 | 65 | NO | YES |
CVE-2020-7373CRITICAL vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists becaus | Oct 30, 2020 | 9.8 | 56 | NO | NO |
CVE-2023-25135CRITICAL vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_ | Feb 3, 2023 | 9.8 | 54 | NO | YES |
Signals from CVEs in this vendor scope (54 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vbulletin.
Media articles that mention a CVE ID that affects a product developed by Vbulletin — matched by CVE ID, not by vendor name.