Exposure of vBulletin
Message boards23
exposure score
1,117
sites use
0
exploited
3
critical
CVEs
4 resultsCVE-2025-48827CRITICALvBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when runningEPSS 75.8%CVE-2025-48828CRITICALCertain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By cEPSS 57.6%CVE-2026-61511CRITICALvBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.phpEPSS 5.6%CVE-2026-9357MEDIUMvBulletin Login cross site scriptingEPSS 0.4%