Known CVE
vBulletin 6.x - Remote Code Execution
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contain an eval injection vulnerability caused by insufficiently restrictive regex filtering in vB5_Template_Runtime::runMaths(), letting unauthenticated remote attackers execute arbitrary PHP code via the pagenav[pagenumber] parameter in ajax/render template route.
CVE-2026-61511
Critical2026CWE-94
cve2026 · vbulletin · rce · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website