Should I use vBulletin?
The store will not work correctly when cookies are disabled. - vbulletin.com
Depends. Only existing vBulletin communities with dedicated admins should keep buying it; a vB6 upgrade can beat a risky migration. New communities should not start here — the security record and clunkiness point to Discourse or XenForo instead.
Confidence
Medium. Based on 40+ public sources: vendor pages, G2/Trustpilot/Reddit reviews, and 2020–2026 security advisories.
Ratings
- Value for money
- Ease of use
- Feature depthInsufficient evidence in reviewed sources
- Support quality
- Security posture
Pricing
Self-hosted (vBulletin 6 / Connect)
License fee — exact price not published in sources reviewed
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierNo
CloudSubscription — vendor markets 'low cost and no commitment'
Best for
- →Existing vBulletin 4/5 sites upgrading to vB6
- →Large classic discussion forums with dedicated admins
- →Hobbyist communities wanting self-hosted control
Not for
- ×New communities starting from scratch
- ×Teams without sysadmins or patch discipline
- ×Anyone handling security-sensitive member data
- ×Modern chat-first audiences (Discord/Slack)
Gotchas - check before you buy
high
Self-hosted means you own emergency patching; pre-auth RCEs exploited in the wild
high
Public PoC exploits circulate for patched flaws — patch immediately, not eventually
high
Running EOL vBulletin 5 invites compromise; hacked vB 5.7.5 sites documented
medium
License terms can change unilaterally; Reddit reports sales disputes
Pros and cons
Pros
- +Cloud option with 'low cost and no commitment' per vendor
- +Self-hosted and vendor-hosted Cloud deployment choices
- +G2 reviewers call Connect stable and easy to use
- +Two-decade track record powering long-running forums
Cons
- −Repeated critical pre-auth RCE vulnerabilities, several with public exploits
- −Former buyers publicly regret purchasing vBulletin 6
- −Reddit users call it too clunky
- −Proprietary paid license with no free tier
- −vBulletin 5 is end of life, forcing upgrade costs
Sources & method
Analyzed 9/29/2026 - 14 sources - Poor record: multiple pre-auth RCE CVEs from 2020–2026, several actively exploited with exploits; no security page found on site.
official x3review x5security x5news x1
- CVE-2020-17496 pre-auth RCE exploited in the wild, Unit 42 documented real-world exploitation of the September 2020 pre-auth RCE.
- CVE-2025-48827 and CVE-2025-48828 exploits, SANS ISC covered exploit activity against vBulletin in June 2025.
- CVE-2026-61511 template runtime RCE, Public exploit released for a patched vBulletin flaw; SentinelOne tracks the CVE.
- CVE-2023-25135 RCE, Remote code execution vulnerability detailed by SentinelOne.
- KIS-2026-13 runMaths RCE (vBulletin <= 6.2.1), Researcher-published remote code execution affecting current 6.x versions.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.