CVE-2026-61511
CVSS 9.8 CRITICAL: vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the…
Vulnerabilities & Exploits · Zero-Day Exploit
A public exploit turns this from a patchable flaw into an immediate takeover risk. A normal forum request can now be used to push attacker-controlled text into template rendering, where vBulletin treats it as code and executes PHP before anyone logs in.
The issue is CVE-2026-61511 in vBulletin's template engine. It affects vBulletin 5.x through 5.7.5 and 6.x through 6.2.1, and the vendor has already shipped 6.2.2 as the fix.
The standard forum threat model does not hold here. An exposed, unpatched vBulletin host can become a beachhead into the rest of the server and any adjacent web assets that sit behind it.
2 sources · Jul 28
CVSS 9.8 CRITICAL: vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the…
BleepingComputer
vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering.
originalThe Hacker News
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Public exploit details show how CVE-2026-61511 reaches PHP eval() in unpatched vBulletin forums through a visitor-controlled template value.
originalPart of the PlainSec briefing for 2026-07-28
Every edition of this story: Public Exploit Turns vBulletin Into a Server Foothold