CVE-2015-7808: vBulletin
High severity, CVSS 7.5. EPSS: 80.6% chance of exploitation in the next 30 days.
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.
Affected products
- vBulletin vBulletin: version 5.0.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.3 only; version 5.0.4 only; version 5.0.5 only; …
Published 2015-11-24. Last modified 2026-06-17.