Reported by Bleeping Computer. A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering, posing a significant risk to online communities and discussion boards.The security issue, tracked as CVE-2026-61511, affects vBulletin versions 5.x and 6.x. Independent researcher Egidio Romano discovered the flaw, which stems from the 'runMaths()' function improperly sanitizing user input before passing it to PHP's eval() function. Attackers can exploit this by sending a crafted request to the 'ajax/render/[template]' endpoint, leading to remote code execution. A public proof-of-concept exploit is available, increasing the risk of exploitation against unpatched servers. This follows previous exploitation of critical vBulletin flaws in May 2025. vBulletin released version 6.2.2 on July 1, addressing the vulnerability, with patches backported to earlier 6.x releases. However, updates for the 5.x branch are not expected.Source: Bleeping Computer
Threat Intelligence, Vulnerability Management, Patch/Configuration Management
vBulletin forum software vulnerable to remote code execution

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



