Home
CRITICAL: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDefault status
unknown
5.0.0 (custom)
affected
6.0.0 (custom)
affected
Description
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.
Problem types
CWE-424 Improper Protection of Alternate Path
Product status
5.0.0 (custom)
6.0.0 (custom)
References
blog.kevintel.com/vbulletin-replaceadtemplate-kev/
karmainsecurity.com/...l-that-protected-method-vbulletin-rce