Skip to main content
CyberConfirmedHighDevelopingFeatured
10.0

Public exploit released for critical unauthenticated RCE vulnerability in vBulletin

A proof-of-concept exploit has been released for a critical vulnerability in vBulletin that allows unauthenticated remote code execution via a single request to the PHP eval() function. The vulnerability poses a high risk to self-hosted instances, as it requires no user interaction or authentication to trigger. Immediate patching is required to mitigate potential exploitation.

The Hacker Newsabout 2 hours agoCredibility 52%View source

Score Breakdown

Mosaic Score10.0
Confidence0.9
Significance0.8
Source credibility0.5
Source

Related signals

8 found