CVE-2017-7569: vBulletin

High severity, CVSS 8.6. EPSS: 1.2% chance of exploitation in the next 30 days.

In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.

Affected products

  • vBulletin vBulletin: up to and including 5.2.6

Published 2017-04-06. Last modified 2026-06-17.