Exposure of vBulletin
Message boards25
exposure score
1,282
sites use
0
exploited
3
critical
CVEs
4 resultsCVE-2025-48827CRITICALvBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when runningEPSS 77.4%CVE-2025-48828CRITICALCertain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By cEPSS 60.3%CVE-2026-61511CRITICALvBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.phpEPSS 1.3%CVE-2026-9357MEDIUMvBulletin Login cross site scriptingEPSS 0.3%