CVE-2025-48828 Details
Description
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.
A remote code execution vulnerability has been identified in vBulletin versions 5.0.0 through 6.0.3. This vulnerability arises from the improper handling of template conditionals in the template engine, which allows attackers to execute arbitrary PHP code. By crafting template code that exploits an alternative PHP function invocation syntax, such as using 'var_dump' as a string argument, attackers can bypass security checks and execute malicious code. This vulnerability has been actively exploited in the wild since May 2025.
Users can update to vBulletin versions 6.0.3 Patch Level 1, 6.0.2 Patch Level 1, 6.0.1 Patch Level 1, or 5.7.5 Patch Level 3, all of which include the necessary fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.kevintel.com/vbulletin-replaceadtemplate-kev/ | CISA-ADP | Broken Link |
| https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce | [email protected] | ExploitThird Party Advisory |
| https://kevintel.com/CVE-2025-48828 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-424 | Improper Protection of Alternate Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vbulletin vbulletin | 6.0.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | Initial Analysis | [email protected] |
| May 27, 2025 | CVE Modified | CISA-ADP |
| May 27, 2025 | CVE Modified | [email protected] |
| May 27, 2025 | New CVE Received | [email protected] |