CVE-2026-61511
vBulletin 5.x and 6.x versions up to 5.7.5 and 6.2.1 contain a critical flaw that lets anyone on the internet run arbitrary PHP code on the server. The bug is triggered by sending a specially crafted value in the pagenav[pagenumber] parameter to the ajax/render template route. Because no authentication is required, attackers can take full control of the affected site.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
vBulletin forum software versions 5.x up to 5.7.5 and 6.x up to 6.2.1, used by website owners running community forums.
Real-world impact
An attacker could run any PHP code on the server, giving them full control over the website, its data, and potentially the underlying operating system.
Why this severity
The CVSS score of 9.3 reflects that the vulnerability is exploitable over the network without authentication, has high impact on confidentiality, integrity, and availability, and allows attackers to execute arbitrary code.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 27, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 16h agoAdvisory updatedThe NVD record was last revised.