CVE-2025-48827
27.05.2025, 04:15
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.Enginsight
Vendor | Product | Version |
---|---|---|
vbulletin | vbulletin | 5.0.0 ≤ 𝑥 ≤ 5.7.5 |
vbulletin | vbulletin | 6.0.0 ≤ 𝑥 ≤ 6.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration