Threat Intelligence, Vulnerability Management, Patch/Configuration Management

vBulletin forum software vulnerable to remote code execution

Real Php code developing screen. Programing workflow abstract algorithm concept. Lines of Php code visible under magnifying lens.

Reported by Bleeping Computer. A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering, posing a significant risk to online communities and discussion boards.

The security issue, tracked as CVE-2026-61511, affects vBulletin versions 5.x and 6.x. Independent researcher Egidio Romano discovered the flaw, which stems from the 'runMaths()' function improperly sanitizing user input before passing it to PHP's eval() function. Attackers can exploit this by sending a crafted request to the 'ajax/render/[template]' endpoint, leading to remote code execution. A public proof-of-concept exploit is available, increasing the risk of exploitation against unpatched servers. This follows previous exploitation of critical vBulletin flaws in May 2025. vBulletin released version 6.2.2 on July 1, addressing the vulnerability, with patches backported to earlier 6.x releases. However, updates for the 5.x branch are not expected.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds