CVE-2016-6195: vBulletin

Critical severity, CVSS 9.8. EPSS: 68.5% chance of exploitation in the next 30 days.

SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.

Affected products

  • vBulletin vBulletin: up to and including 4.2.2; version 4.2.3 only

Published 2016-08-30. Last modified 2026-06-17.