CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-61511: vBulletin Pre-Auth Remote Code Execution via Template Engine

July 27, 2026

CVE-2026-61511 is an unauthenticated remote code execution vulnerability in vBulletin's template engine, specifically in the vB5_Template_Runtime::runMaths() method. The flaw allows an attacker to inject PHP code through the ajax/render/pagenav route without authentication. vBulletin patched the issue in versions 6.2.2, 6.2.1, 6.2.0, and 6.1.6. A public exploit was released on July 27, 2026.