The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options.
No PoCs from references.
- https://github.com/404notf0und/CVE-Flow