AI description
CVE-2026-61511 is an eval injection vulnerability affecting vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1. The flaw resides within the `vB5_Template_Runtime::runMaths()` method in the template runtime, where an insufficiently restrictive regular expression filter allows crafted input to bypass intended character restrictions before being processed by PHP's `eval()` function. Unauthenticated remote attackers can exploit this vulnerability to execute arbitrary PHP code. This is achieved by supplying specially crafted input through the `pagenav[pagenumber]` parameter via the unauthenticated `ajax/render` template route. No authentication, session, or user interaction is required for successful exploitation, and attackers can utilize phpfuck-style encoding to construct their payloads.
- Description
- vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
- Source
- disclosure@vulncheck.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- disclosure@vulncheck.com
- CWE-95
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
5
๐จ CVE-2026-61511: A critical unauthenticated RCE vulnerability affects vBulletin 5.x/6.x via runMaths eval injection. #vBulletin #RCE #CVE #CyberSecurity
@ThreatWire_
2 Aug 2026
2268 Impressions
2 Retweets
15 Likes
4 Bookmarks
0 Replies
0 Quotes
CVE-2026-61511: critical unauthenticated RCE in vBulletin 5.x/6.x via runMaths eval injection. Get the Nuclei detection template and scan with Sn1per. https://t.co/sCsYL3Uv5L #CVE-2026-61511 #bugbounty #redteam #offsec #netsec #infosec #poc https://t.co/JxdGQfBs0G
@xer0dayz
1 Aug 2026
1077 Impressions
7 Retweets
21 Likes
7 Bookmarks
0 Replies
0 Quotes
CVE-2026-61511: critical unauthenticated RCE in vBulletin 5.x/6.x via runMaths eval injection. Get the Nuclei detection template and scan with Sn1per. https://t.co/48xuw7wyMA #CVE-2026-61511 #bugbounty #redteam #offsec #netsec #infosec #poc https://t.co/g8tw8MVx2A
@Sn1perSecurity
1 Aug 2026
135 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ๐จ๐จ๐จ # CVE-2026-61511 #vBulletin RCE Exploit Kit CVE-2026-61511 is an unauthenticated Remote Code Execution vulnerability in vBulletin forums affecting versions 5.0.0-5.7.5 and 6.0.0-6.2.1. Look who's back ๐ BrokenSecยฎ #0days #exploit #RCE #CVE #security #hacki
@YogSoth0
29 Jul 2026
805 Impressions
5 Retweets
21 Likes
7 Bookmarks
3 Replies
0 Quotes
๐จ CVE-2026-61511: vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php Critical Vulnerability Alert! vBulletin is affected by CVE-2026-61511. Full Vulnerability Details & Analysis at DarkEye: ๐ https://t.co/PheaYhNSYY ๐ Identify Targets via ZoomEye
@zoomeye_team
28 Jul 2026
1267 Impressions
4 Retweets
14 Likes
2 Bookmarks
0 Replies
0 Quotes
Public exploit details for CVE-2026-61511 show an unauthenticated RCE in vBulletin's template engine, reaching PHP eval() via vB5_Template_Runtime::runMaths(). Affects unpatched forums. #vBulletin #CVE-2026-61511 #PHP https://t.co/Cmte8v93jZ
@TweetThreatNews
27 Jul 2026
188 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ CVE-2026-61511 โ CVSS 9.8/10 โโโโโโโโโโ vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/gvOFCwbyGb
@OrizonCyber
27 Jul 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes