CVE-2026-61511
CVSS 9.8 CRITICAL: vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the…
Vulnerabilities · 48 days ago
A public exploit turns this from a patchable flaw into an immediate takeover risk. A normal forum request can now be used to push attacker-controlled text into template rendering, where vBulletin treats it as code and executes PHP before anyone logs in.
The issue is CVE-2026-61511 in vBulletin's template engine. It affects vBulletin 5.x through 5.7.5 and 6.x through 6.2.1, and the vendor has already shipped 6.2.2 as the fix.
The standard forum threat model does not hold here. An exposed, unpatched vBulletin host can become a beachhead into the rest of the server and any adjacent web assets that sit behind it.
CVSS 9.8 CRITICAL: vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the…
2 sources covering this story
vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering.
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Public exploit details show how CVE-2026-61511 reaches PHP eval() in unpatched vBulletin forums through a visitor-controlled template value.
Part of the PlainSec briefing for 2026-07-29