Skip to content

Known CVE

vBulletin 6.x - Remote Code Execution

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contain an eval injection vulnerability caused by insufficiently restrictive regex filtering in vB5_Template_Runtime::runMaths(), letting unauthenticated remote attackers execute arbitrary PHP code via the pagenav[pagenumber] parameter in ajax/render template route.

CVE-2026-61511

Critical2026CWE-94

cve2026 · vbulletin · rce · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website