Back

CVE-2016-6195

CRITICAL

SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.

Published: Aug 30, 2016 Modified: Jun 17, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
vbulletin vbulletin *
vbulletin vbulletin 4.2.3

GitHub Security Advisory GHSA-vhxf-9672-mr6m

SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 68.49%

Top 1% most likely to be exploited

Threat Score 59.7 / 100

Data Sources

NVD EPSS GitHub