Junglewise Threat Intelligence

CVE-2026-9357: vBulletin 6.x cross-site scripting in Login component

CVE-2026-9357 · Severity: low · CVSS 3.5 · Published 2026-05-24

Technologies: Vbulletin. Vendors: Vbulletin.

Executive brief

vBulletin, a widely used community forum software, contains a security vulnerability in its login component. An attacker can use this flaw to perform cross-site scripting (XSS) attacks, which could allow them to execute malicious scripts in the browser of other users. This could lead to unauthorized actions being performed on behalf of users or the theft of session information.

Technical details

A cross-site scripting (XSS) vulnerability exists in the Login component of vBulletin 6.x. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79), which can also lead to code injection (CWE-94). An attacker with low-level privileges can exploit this remotely by manipulating login-related functions, though user interaction is required for the script to execute in the victim's browser. While a public exploit exists, the vendor has reportedly not responded to disclosure attempts, and no official patch is currently confirmed.

Affected products

  • vBulletin vBulletin 6.x

Timeline

  • 2026-05-24: disclosed: Public disclosure via VulDB and NVD
  • 2026-05-24: advisory

References

Related threats