vBulletin 3.7.1 PL1 / vBulletin 3.6.10 PL1 has been released.
From their announcement:
The recent discovery of an obscure method in which to expose a cross-site scripting (XSS) error in vBulletin when using specific browser software means that it is necessary to release Patch Level (PL) versions of both 3.7.1 and 3.6.10.
Although it is difficult to exploit the XSS flaw, and the potential for exposure and damage is limited, we nonetheless recommend that customers upgrade to protect themselves.
Read more / Get it at: vbulletin.com/forum/showthread.php?t=274882