{"cve":"CVE-2026-61511","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[5.0.0,5.7.5]"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[6.0.0,6.2.1]"}},{"platform":null,"status":"unaffected","versions":{"scheme":"semver","value":"6.2.2"}}],"enrichment":{"confidence":100.0,"confidence_source":"matching","scores":[{"score":100.0,"source":"matching"}]},"original":{"product":"vBulletin","source":"cna","vendor":"vBulletin"},"product":"vbulletin","vendor":"vbulletin"}],"created":"2026-07-27T14:58:19.917735+00:00","updated":"2026-08-25T15:30:05.674796+00:00","vendors":["vbulletin","vbulletin$PRODUCT$vbulletin"]},"epss":{"score":0.05607},"mitre":{"cpes":["cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*"],"created":"2026-07-27T12:39:16.085000+00:00","description":"vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2026/61xxx/CVE-2026-61511.json","references":["https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509358-security-patch-released-for-vbulletin-6-2-1-6-2-0-and-6-1-6","https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509404-vbulletin-6-2-2-is-available","https://karmainsecurity.com/KIS-2026-13","https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/","https://www.vulncheck.com/advisories/vbulletin-eval-injection-rce-via-vb5-template-runtime-php"],"title":"vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php","updated":"2026-08-07T05:32:22.940000+00:00","vendors":["vbulletin","vbulletin$PRODUCT$vbulletin"],"weaknesses":["CWE-95"]},"nvd":{"cpes":[],"created":"2026-07-27T14:16:59.177000+00:00","description":"vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-61511.json","references":["http://seclists.org/fulldisclosure/2026/Aug/29","https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509358-security-patch-released-for-vbulletin-6-2-1-6-2-0-and-6-1-6","https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509404-vbulletin-6-2-2-is-available","https://karmainsecurity.com/KIS-2026-13","https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/","https://www.vulncheck.com/advisories/vbulletin-eval-injection-rce-via-vb5-template-runtime-php"],"title":null,"updated":"2026-08-07T06:16:56.993000+00:00","vendors":[],"weaknesses":["CWE-95"]},"opencve":{"changes":[{"created":"2026-07-27T13:45:00+00:00","data":[{"details":{"new":"vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.","old":null},"type":"description"},{"details":{"new":"vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php","old":null},"type":"title"},{"details":{"added":["CWE-95"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509358-security-patch-released-for-vbulletin-6-2-1-6-2-0-and-6-1-6","https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509404-vbulletin-6-2-2-is-available","https://karmainsecurity.com/KIS-2026-13","https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/","https://www.vulncheck.com/advisories/vbulletin-eval-injection-rce-via-vb5-template-runtime-php"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"b1d7fa5b-81a4-44c3-abd6-542274609e55"},{"created":"2026-07-27T14:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"ffae7b81-b7dc-4108-82ac-0016e5a3534f"},{"created":"2026-07-27T15:30:00+00:00","data":[{"details":["vbulletin","vbulletin$PRODUCT$vbulletin"],"type":"first_time"},{"details":{"added":["vbulletin","vbulletin$PRODUCT$vbulletin"],"removed":[]},"type":"vendors"}],"id":"2d14afde-3664-414e-8b80-37464898a795"},{"created":"2026-07-28T02:30:00+00:00","data":[{"details":{"added":["cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"}],"id":"3115b0e9-1418-4fe4-a6bd-080e58973810"},{"created":"2026-07-29T20:30:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"ssvc":{"new":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"old":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}}}},"type":"metrics"}],"id":"2fd6304b-2504-4a16-b30c-cc82f4ac54c3"}],"cpes":{"data":["cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2026-07-27T12:39:16.085000+00:00","provider":"mitre"},"description":{"data":"vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{"score":0.05607},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["http://seclists.org/fulldisclosure/2026/Aug/29","https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509358-security-patch-released-for-vbulletin-6-2-1-6-2-0-and-6-1-6","https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509404-vbulletin-6-2-2-is-available","https://karmainsecurity.com/KIS-2026-13","https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/","https://www.vulncheck.com/advisories/vbulletin-eval-injection-rce-via-vb5-template-runtime-php"],"providers":["mitre","nvd"]},"title":{"data":"vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php","provider":"mitre"},"updated":{"data":"2026-07-29T19:26:41.811000+00:00","provider":"mitre"},"vendors":{"data":["vbulletin","vbulletin$PRODUCT$vbulletin"],"providers":["mitre","enrichment"]},"weaknesses":{"data":["CWE-95"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-07-27T12:39:16.085000+00:00","description":"vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php","updated":"2026-07-27T13:53:20.579000+00:00","vendors":[],"vulnrichment_repo_path":"2026/61xxx/CVE-2026-61511.json","weaknesses":[]}}