vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
We have discovered 1,532 live websites that are affected by CVE-2026-61511.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 1,532 live websites (33% of vBulletin install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 47 versions ( 39% of all versions) |
| 952 websites | |
| 140 websites | |
| 76 websites | |
| 76 websites | |
| 36 websites | |
| 20 websites | |
| 19 websites | |
| 16 websites | |
| 16 websites | |
| 14 websites |
| .com | 782 websites |
| .net | 132 websites |
| .eu | 109 websites |
| .org | 107 websites |
| .de | 69 websites |
| .fr | 51 websites |
| .co.uk | 43 websites |
| .it | 24 websites |
| .info | 16 websites |
| .nl | 15 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | **,*** | ||
| ******.**********.com | **,*** | ||
| ******.******.com | ***,*** | ||
| ********.com | ***,*** | ||
| *****.******.fr | ***,*** | ||
| *****.*********.com | ***,*** | ||
| *******.de | ***,*** | ||
| ****.com | ***,*** | ||
| *******.net | ***,*** | ||
| ********.com | ***,*** |