shouldiuse.io

Categories

VERDICT

Should I use vBulletin?

The store will not work correctly when cookies are disabled. - vbulletin.com

Depends. Only existing vBulletin communities with dedicated admins should keep buying it; a vB6 upgrade can beat a risky migration. New communities should not start here — the security record and clunkiness point to Discourse or XenForo instead.

Confidence

Medium. Based on 40+ public sources: vendor pages, G2/Trustpilot/Reddit reviews, and 2020–2026 security advisories.

Ratings

  • Value for money
  • Ease of use
  • Feature depthInsufficient evidence in reviewed sources
  • Support quality
  • Security posture

Pricing

Self-hosted (vBulletin 6 / Connect)

License fee — exact price not published in sources reviewed

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierNo
CloudSubscription — vendor markets 'low cost and no commitment'

Best for

  • Existing vBulletin 4/5 sites upgrading to vB6
  • Large classic discussion forums with dedicated admins
  • Hobbyist communities wanting self-hosted control

Not for

  • New communities starting from scratch
  • Teams without sysadmins or patch discipline
  • Anyone handling security-sensitive member data
  • Modern chat-first audiences (Discord/Slack)

Gotchas - check before you buy

high

Self-hosted means you own emergency patching; pre-auth RCEs exploited in the wild

high

Public PoC exploits circulate for patched flaws — patch immediately, not eventually

high

Running EOL vBulletin 5 invites compromise; hacked vB 5.7.5 sites documented

medium

License terms can change unilaterally; Reddit reports sales disputes

Pros and cons

Pros

  • Cloud option with 'low cost and no commitment' per vendor
  • Self-hosted and vendor-hosted Cloud deployment choices
  • G2 reviewers call Connect stable and easy to use
  • Two-decade track record powering long-running forums

Cons

  • Repeated critical pre-auth RCE vulnerabilities, several with public exploits
  • Former buyers publicly regret purchasing vBulletin 6
  • Reddit users call it too clunky
  • Proprietary paid license with no free tier
  • vBulletin 5 is end of life, forcing upgrade costs

Sources & method

Analyzed 9/29/2026 - 14 sources - Poor record: multiple pre-auth RCE CVEs from 2020–2026, several actively exploited with exploits; no security page found on site.

official x3review x5security x5news x1
  • CVE-2020-17496 pre-auth RCE exploited in the wild, Unit 42 documented real-world exploitation of the September 2020 pre-auth RCE.
  • CVE-2025-48827 and CVE-2025-48828 exploits, SANS ISC covered exploit activity against vBulletin in June 2025.
  • CVE-2026-61511 template runtime RCE, Public exploit released for a patched vBulletin flaw; SentinelOne tracks the CVE.
  • CVE-2023-25135 RCE, Remote code execution vulnerability detailed by SentinelOne.
  • KIS-2026-13 runMaths RCE (vBulletin <= 6.2.1), Researcher-published remote code execution affecting current 6.x versions.

Key stats

  • Value for money: 2/5

    Rating

  • License fee — exact price not published in sources reviewed

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 2/5. Buyers publicly report regret after purchase
  • Ease of use: 3/5. G2 praises stability; Reddit calls it clunky
  • Feature depth. Insufficient evidence in reviewed sources
  • Support quality: 2/5. Reddit users report unhelpful sales experiences
  • Security posture: 1/5. Repeated actively exploited pre-auth RCEs
  • 4.0/5 Community rating Per Raklet comparison, 2026
  • No Free tier Proprietary, licensed software
  • 6+ Pre-auth RCE CVEs since 2020 Several with public exploits

Pricing

Self-hosted (vBulletin 6 / Connect)

License fee — exact price not published in sources reviewed

  • Buy via vendor store
  • You host, maintain, and patch

Cloud

Subscription — vendor markets 'low cost and no commitment'

  • Vendor-hosted
  • No server maintenance

Security

Poor record: multiple pre-auth RCE CVEs from 2020–2026, several actively exploited with exploits; no security page found on site.

  • CVE-2020-17496 pre-auth RCE exploited in the wildUnit 42 documented real-world exploitation of the September 2020 pre-auth RCE.⁹
  • CVE-2025-48827 and CVE-2025-48828 exploitsSANS ISC covered exploit activity against vBulletin in June 2025.11
  • CVE-2026-61511 template runtime RCEPublic exploit released for a patched vBulletin flaw; SentinelOne tracks the CVE.12
  • CVE-2023-25135 RCERemote code execution vulnerability detailed by SentinelOne.
  • KIS-2026-13 runMaths RCE (vBulletin <= 6.2.1)Researcher-published remote code execution affecting current 6.x versions.13

Alternatives

Compare vBulletin with each alternative.

  • phpBB

    Free classic self-hosted forum software

Companies that use it

  • FreeBSD
Full analysis

Based on 40+ public sources: vendor pages, G2/Trustpilot/Reddit reviews, and 2020–2026 security advisories.

Legacy forum software: workable but a security liability. Existing vB sites may stay; new communities should pick Discourse or XenForo.

Methodology

Based on 40+ public sources: vendor pages, G2/Trustpilot/Reddit reviews, and 2020–2026 security advisories.

Sources

  1. official
  2. Buy vBulletin 6vbulletin.com
    official
  3. vBulletin — Wikipediaen.wikipedia.org
    official
  4. review
  5. review
  6. review
  7. review
  8. review
  9. security
  10. security
  11. security
  12. security
  13. security
  14. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.