PoC public vBulletin rce web-app
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
CVE Tools coverage
A public exploit has been shared for a patched remote code execution vulnerability in vBulletin, allowing attackers to execute arbitrary code without authentication. The flaw affects versions up to 6.2.1 and 6.1.6, with patches available since late June 2026. Despite the availability of fixes, unpatched self-hosted installations remain at risk. The vulnerability resides in the template engine’s handling of inline math expressions, enabling malicious users to bypass filters and trigger PHP's eval() function. While no active exploitation has been confirmed yet, the release of the proof-of-concept increases the likelihood of real-world attacks.