CVE-2014-2023: Tapatalk

Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in mobiquo/functions/.

Affected products

  • Tapatalk Tapatalk: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.1.0 only; version 1.1.1 only; version 1.1.2 only; …

Published 2017-10-26. Last modified 2026-06-17.