← Back to browse · API

CVE-2025-48828

Severity
CRITICAL
CVSS
9.0
EPSS
0.6025
Risk score
57.09
CISA KEV
No
PoC
No
Published
2025-05-27
Modified
2025-05-27
First seen
2026-08-07
Aliases
EUVD-2025-28268, GHSA-58PJ-RCXG-3VHG
Products
vBulletin:vBulletin 6.0.3
Sources
euvd EUVD-2025-28268

Description

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.

References