CVE-2026-61511
published 2026-07-27CVE-2026-61511: vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template…
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
70.77%
99.4th percentile
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vbulletin | vbulletin | 5.0.0 – 5.7.5 | — |
| vbulletin | vbulletin | 6.0.0 – 6.2.1 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote
ghsa_unreviewed·2026-07-27
CVE-2026-61511 [CRITICAL] CWE-95 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
VulDB
vBulletin up to 5.7.5/6.2.1 Template Runtime runMaths pagenav[pagenumber] code injection (WID-SEC-2026-2528)
vuldb·2026-07-27·CVSS 9.8
CVE-2026-61511 [CRITICAL] vBulletin up to 5.7.5/6.2.1 Template Runtime runMaths pagenav[pagenumber] code injection (WID-SEC-2026-2528)
A vulnerability classified as critical has been found in vBulletin up to 5.7.5/6.2.1. Affected by this issue is the function vB5_Template_Runtime::runMaths of the component Template Runtime. The manipulation of the argument pagenav[pagenumber] leads to code injection.
This vulnerability is uniquely identified as CVE-2026-61511. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
VulnCheck
vBulletin vBulletin Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
vulncheck·2026·CVSS 9.8
CVE-2026-61511 [CRITICAL] vBulletin vBulletin Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
vBulletin vBulletin Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
Affected: vBulletin vBulletin
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the prod
No detection rules found.
Nuclei
vBulletin 6.x - Remote Code Execution
nuclei·CVSS 9.8
CVE-2026-61511 [CRITICAL] vBulletin 6.x - Remote Code Execution
vBulletin 6.x - Remote Code Execution
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contain an eval injection vulnerability caused by insufficiently restrictive regex filtering in vB5_Template_Runtime::runMaths(), letting unauthenticated remote attackers execute arbitrary PHP code via the pagenav[pagenumber] parameter in ajax/render template route.
Template:
id: CVE-2026-61511
info:
name: vBulletin 6.x - Remote Code Execution
author: 0x_Akoko
severity: critical
description: |
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contain an eval injection vulnerability caused by insufficiently restrictive regex filtering in vB5_Template_Runtime::runMaths(), letting unauthenticated remote attackers execute arbitrary PHP code via the pagenav[pagenumber] parameter in ajax/render template r
Hackernews
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
blogs_hackernews·2026-08-03
CVE-2026-42897 ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.
Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from forum chatter to real targets.
The full weekly recap report follows.
## ⚡ Threat of the Week
Anthropic Disclosed its Models Targeted 3 O
Hackernews
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
blogs_hackernews·2026-07-27·CVSS 9.8
CVE-2026-61511 [CRITICAL] Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
eval()
SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version boundary. vBulletin issued security patches for 6.2.1, 6.2.0, and 6.1.6 at the end of June and released the fixed version 6.2.2 on July 1, nearly four weeks before the exploit went public
Administrators running self-hosted installations should apply the patch for their branch or upgrade to 6.2.2. vBulletin says its Cloud sites have already been patched against the flaw.
SSD did not report active exploitation. As of Ju
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509358-security-patch-released-for-vbulletin-6-2-1-6-2-0-and-6-1-6https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509404-vbulletin-6-2-2-is-availablehttps://karmainsecurity.com/KIS-2026-13https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/https://www.vulncheck.com/advisories/vbulletin-eval-injection-rce-via-vb5-template-runtime-phphttp://seclists.org/fulldisclosure/2026/Aug/29
2026-07-27
Published
Exploited in the wild