CVE-2026-61511 is a critical unauthenticated remote code execution vulnerability in vBulletin affecting 5.x through 5.7.5 and 6.x through 6.2.1. The flaw resides in the template runtime, specifically the vB5_Template_Runtime::runMaths() method used to process inline math expressions for the {vb:math} template tag. The method applies an insufficiently restrictive regular-expression filter and then passes the resulting expression to PHP's eval() function. Because the filter still permits a limited set of characters sufficient to reconstruct executable PHP expressions using phpfuck-style techniques, an attacker can supply crafted input that survives filtering and is evaluated as PHP code. The issue is reachable without authentication through public template-rendering paths, including the ajax/render route, and can be triggered via attacker-controlled input supplied through the pagenav[pagenumber] parameter in the pagenav template path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated remote code execution vulnerability in vBulletin caused by inadequate filtering in the vB5_Template_Runtime::runMaths() method before passing input to PHP eval(), allowing attacker-controlled PHP code execution via the {vb:math} template tag.
An unauthenticated remote code execution vulnerability in vBulletin's template engine that allows a public request to reach PHP eval() via the ajax/render/pagenav route and execute code on unpatched self-hosted forum servers.
An unauthenticated remote code execution vulnerability in vBulletin's template runtime, caused by eval injection in vB5_Template_Runtime::runMaths(), allowing arbitrary PHP code execution via crafted pagenav[pagenumber] input.
A critical remote code execution vulnerability in vBulletin that allows unauthenticated attackers to execute arbitrary code on a remote server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.