{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/vbulletin--6.1.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*","cpe:2.3:a:vbulletin:vbulletin:6.0.3:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-61511"},{"cvss":10,"id":"CVE-2025-48827"},{"cvss":9,"id":"CVE-2025-48828"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":[],"_cs_products":["vBulletin 5.x through 5.7.5","vBulletin 6.x through 6.2.1","vBulletin (\u003c 6.2.2)","vBulletin (\u003c 6.1.7)","vBulletin Cloud"],"_cs_severities":["critical"],"_cs_tags":["web-vulnerability","remote-code-execution","eval-injection","php","unauthenticated"],"_cs_type":"advisory","_cs_vendors":["vBulletin"],"content_html":"\u003cp\u003eA critical eval injection vulnerability (CVE-2026-61511) has been discovered in vBulletin versions 5.x up to 5.7.5 and 6.x up to 6.2.1. This flaw resides within the \u003ccode\u003evB5_Template_Runtime::runMaths()\u003c/code\u003e method of the template runtime engine. Unauthenticated remote attackers can leverage this vulnerability to execute arbitrary PHP code on affected vBulletin instances. The attack vector involves supplying specially crafted input through the \u003ccode\u003epagenav[pagenumber]\u003c/code\u003e parameter via the unauthenticated \u003ccode\u003eajax/render\u003c/code\u003e template route. Attackers can bypass existing regex filters designed to sanitize input by utilizing \u0026quot;phpfuck-style\u0026quot; encoding techniques, which use a limited set of characters to construct and execute complex PHP payloads. This vulnerability poses a severe risk as it allows for complete compromise of the vBulletin server without requiring any prior authentication, making it highly attractive to threat actors targeting forums and community platforms.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a vulnerable vBulletin instance running versions 5.x up to 5.7.5 or 6.x up to 6.2.1.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP POST request targeting the \u003ccode\u003e/ajax/render\u003c/code\u003e template route of the vBulletin application.\u003c/li\u003e\n\u003cli\u003eThe crafted request includes the \u003ccode\u003epagenav[pagenumber]\u003c/code\u003e parameter, manipulated to contain a PHP payload obfuscated using \u0026quot;phpfuck-style encoding\u0026quot; or other command injection techniques.\u003c/li\u003e\n\u003cli\u003eThe vBulletin application receives the request, and the \u003ccode\u003evB5_Template_Runtime::runMaths()\u003c/code\u003e method attempts to process the value of the \u003ccode\u003epagenav[pagenumber]\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eDue to the eval injection vulnerability and insufficient regex filtering, the application incorrectly evaluates the attacker's input as executable PHP code.\u003c/li\u003e\n\u003cli\u003eThe injected PHP code then executes arbitrary system commands or functions provided by the attacker on the underlying server.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves unauthenticated remote code execution, gaining full control over the compromised vBulletin web server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eA successful exploitation of CVE-2026-61511 grants unauthenticated remote code execution (RCE) on the affected vBulletin server. This can lead to complete compromise of the server, including data theft, defacement, installation of backdoors, deployment of web shells, or further network penetration. For forum owners, this means sensitive user data (usernames, email addresses, hashed passwords, private messages) can be exfiltrated. The integrity and availability of the vBulletin application can be severely degraded or destroyed. Given the widespread use of vBulletin for online communities, a large number of organizations globally are potentially at risk, though specific victim counts are not yet available.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-61511 by updating vBulletin installations to a patched version beyond 5.7.5 or 6.2.1 immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-61511 Exploitation - vBulletin Eval Injection\u0026quot; to your SIEM to detect exploitation attempts targeting the \u003ccode\u003eajax/render\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive web server logging, including full request URLs, headers, and body content where possible, to ensure the \u003ccode\u003ewebserver\u003c/code\u003e log source captures necessary details for detecting \u003ccode\u003ecs-uri-stem\u003c/code\u003e and \u003ccode\u003ecs-uri-query\u003c/code\u003e patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T15:42:03Z","date_published":"2026-07-27T14:19:04Z","id":"https://feed.craftedsignal.io/briefs/2026-07-vbulletin-eval-injection/","summary":"An eval injection vulnerability, identified as CVE-2026-61511, exists in vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1, specifically within the vB5_Template_Runtime::runMaths() method, allowing unauthenticated remote attackers to achieve arbitrary PHP code execution by manipulating the pagenav[pagenumber] parameter through the unauthenticated ajax/render template route with phpfuck-style encoding.","title":"Critical Eval Injection Vulnerability in vBulletin Allows Remote Code Execution (CVE-2026-61511)","url":"https://feed.craftedsignal.io/briefs/2026-07-vbulletin-eval-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - VBulletin (\u003c 6.1.7)","version":"https://jsonfeed.org/version/1.1"}