top of page
perceptive_background_267k.jpg

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template ru…

Published:

26 juli 2026 om 22:00:00

Alert date:

27 juli 2026 om 21:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities, Enterprise Applications

CVE-2026-61511 is a critical eval injection vulnerability affecting vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1. The flaw resides in the vB5_Template_Runtime::runMaths() method within the template runtime engine. Unauthenticated remote attackers can exploit this vulnerability by supplying crafted input via the pagenav[pagenumber] parameter. The insufficiently restrictive regex filter can be bypassed using phpfuck-style encoding with permitted characters, allowing arbitrary PHP code injection. Exploitation occurs through the unauthenticated ajax/render template route, requiring no credentials. This makes the vulnerability particularly dangerous as it is remotely and freely exploitable. Patches have been released by vBulletin for affected versions including 6.2.0, 6.2.1, and 6.1.6, with version 6.2.2 also made available. Multiple security researchers and disclosure sources have documented this vulnerability.

Technical details

Mitigation steps:

Affected products:

vBulletin 5.x through 5.7.5
vBulletin 6.x through 6.2.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page