CVE-2025-48828
97Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9epss 60%
from disclosure to weapon29 days
Published on NVDMay 27
1st PoC+29d
metasploitMay 23
VulnCheckMay 26
exploitation probability
60%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
vBulletin · vBulletinpublic PoCs found — 3
githubgithub.com/ill-deed/vBulletin-CVE-2025-48828-Multi-target★ 0cve_referenceblog.kevintel.com/vbulletin-replaceadtemplate-kev/unverifiedvulncheckvulncheck.com/xdb/65e29379639aunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.