PT-2026-42915 · Vbulletin · Vbulletin

Chor4O

·

Published

2026-05-24

·

Updated

2026-05-24

·

CVE-2026-9357

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions vBulletin versions 6.x
Description A flaw in the Login component allows a remote attacker to perform a manipulation that results in cross-site scripting (XSS), which is a technique where malicious scripts are injected into trusted websites.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9357

Affected Products

Vbulletin