CVE-2025-48828

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vbulletin:vbulletin:6.0.3:*:*:*:*:*:*:*

History

25 Jun 2025, 16:32

Type Values Removed Values Added
References () https://blog.kevintel.com/vbulletin-replaceadtemplate-kev/ - () https://blog.kevintel.com/vbulletin-replaceadtemplate-kev/ - Broken Link
References () https://kevintel.com/CVE-2025-48828 - () https://kevintel.com/CVE-2025-48828 - Third Party Advisory
References () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce - () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
First Time Vbulletin
Vbulletin vbulletin
CPE cpe:2.3:a:vbulletin:vbulletin:6.0.3:*:*:*:*:*:*:*

27 May 2025, 18:15

Type Values Removed Values Added
References
  • () https://blog.kevintel.com/vbulletin-replaceadtemplate-kev/ -

27 May 2025, 13:15

Type Values Removed Values Added
References
  • () https://kevintel.com/CVE-2025-48828 -
CWE CWE-424
Summary Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code. Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.

27 May 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-27 04:15

Updated : 2025-06-25 16:32


NVD link : CVE-2025-48828

Mitre link : CVE-2025-48828


JSON object : View

Products Affected

vbulletin

  • vbulletin
CWE

No CWE.