S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-61511 Scanner

CVE-2026-61511 Scanner - Remote Code Execution (RCE) vulnerability in vBulletin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-61511
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
vBulletinby vBulletin
5.0.0
Updated Sep 11, 2026View on NVD →
Detail

vBulletin is an internet forum software widely used by organizations and individual communities to create interactive and customizable forums. It is designed to be user-friendly, scalable, and secure, and can be customized and integrated with various functionalities to serve as a complete community platform. By utilizing vBulletin, users can manage discussions, user interactions, and community engagement effectively. Commonly used by businesses, educational institutions, and professional communities, vBulletin supports high traffic and multiple integrations. It aims to provide an easy and interactive platform for building online communities.

The Remote Code Execution (RCE) vulnerability in vBulletin allows unauthenticated users to execute arbitrary PHP code remotely. This vulnerability arises due to insufficiently restrictive regex filtering in the function used to handle parameterized requests. Attackers can manipulate certain parameters in HTTP requests to run malicious code on the affected server. As a critical vulnerability, it can lead to full system compromise when exploited. Administrators must update affected vBulletin versions to prevent potential exploitation.

Technical details include exploitation through improperly restricted regex filters in the vBulletin Template Runtime system. The attack vector involves the 'pagenav[pagenumber]' parameter, which is susceptible to manipulation, enabling attackers to insert and execute PHP code. By crafting a malicious payload using regex patterns, attackers can compromise the system. Effective detection involves sending crafted POST requests to the vulnerable endpoint, checking for a specific status code and response content to confirm exploitation.

Exploiting this vulnerability can result in severe consequences, including unauthorized access to system files, modifications to forum databases, and full control over the server. Attackers can execute commands leading to data theft, server misuse, installation of malware, and potential network infiltration. The vulnerability can disrupt services, compromise sensitive information, and degrade user trust due to unauthorized actions taken within the forum environment.

REFERENCES

Solution Advice
  • Immediately update your vBulletin installation to a secure version beyond 6.2.1 or the most recent version available.
  • Implement strict input validation measures to prevent unauthorized code execution through parameterized requests.
  • Regularly audit and monitor logs for unauthorized or suspicious activities to detect early signs of exploitation.
  • Consider using Web Application Firewalls (WAF) to help mitigate and observe anomalous behaviors targeting this vulnerability.
  • Educate and train the system administrators responsible for maintaining the vBulletin software about the latest security best practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-61511 Scanner - Remote Code Execution (RCE) vulnerability in vBulletin | S4E