Vulnerabilities · 48 days ago

Public Exploit Turns vBulletin Into a Server Foothold

A public exploit turns this from a patchable flaw into an immediate takeover risk. A normal forum request can now be used to push attacker-controlled text into template rendering, where vBulletin treats it as code and executes PHP before anyone logs in.

The issue is CVE-2026-61511 in vBulletin's template engine. It affects vBulletin 5.x through 5.7.5 and 6.x through 6.2.1, and the vendor has already shipped 6.2.2 as the fix.

The standard forum threat model does not hold here. An exposed, unpatched vBulletin host can become a beachhead into the rest of the server and any adjacent web assets that sit behind it.

CVE-2026-61511

NVD KEV

CVSS 9.8 CRITICAL: vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the…

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-29

Editions

Related stories