CVE-2020-25115: vBulletin

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.

Affected products

Published 2020-09-03. Last modified 2026-06-17.