Total vulnerabilities in the database
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.
Software | From | Fixed in |
---|---|---|
vbulletin / vbulletin | 5.0.0 | 5.7.5.x |
vbulletin / vbulletin | 6.0.0 | 6.0.3.x |