Vulnerabilities > Vbseo

DATE CVE VULNERABILITY TITLE RISK
2020-02-10 CVE-2012-6666 Cross-site Scripting vulnerability in Vbseo 3.8.7
vBSeo before 3.6.0PL2 allows XSS via the member.php u parameter.
network
low complexity
vbseo CWE-79
6.1
2017-09-15 CVE-2014-9463 Code Injection vulnerability in Vbseo
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php.
network
low complexity
vbseo CWE-94
8.8