Two critical vulnerabilities affecting the open source software vBulletin were recently discovered, with one confirmed to already be actively exploited by attackers.
See also: Details of Cisco IOS XE flaw released publicly

The vulnerabilities, which have been registered as CVE-2025-48827 and CVE-2025-48828, and have been classified as critical (with CVSS v3 scores: 10.0 and 9.0 respectively), are related to malicious API method invocation and remote code execution (RCE), through abuse of the template engine.
They affect vBulletin versions 5.0.0 to 5.7.5 and 6.0.0 to 6.0.3when running PHP 8.1 or later. The vulnerabilities were likely silently patched last year with the release of Patch Level 1 for all versions of the 6.* series and Patch Level 3 for version 5.7.5. However, many websites remain vulnerable as they have not been updated.
The two issues were discovered on May 23, 2025 by security researcher Egidio Romano (aka EgiX), who explained how to exploit them via a detailed technical post on his blog.
The researcher showed that the vulnerabilities are due to vBulletin's misuse of PHP's Reflection API. Due to changes in PHP behavior since version 8.1, protected methods can be called without the required accessibility.
See also: GitLab Duo vulnerability allows manipulation of AI responses
The vulnerability chain relies on the ability to call protected methods via properly crafted URLs and the abuse of conditionals within vBulletin's template engine. By injecting specially crafted template code via the vulnerable 'replaceAdTemplate ' method, attackers can bypass " unsafe function " filters using techniques such as PHP's mutable functions.

This results in complete, remote, and unauthenticated code execution on the underlying server — essentially giving attackers shell access with web server user privileges (e.g. www-data on Linux).
On May 26, security researcher Ryan Dewhurst reported that he detected exploitation attempts in the logs of a honeypot, via requests to the vulnerable endpoint 'ajax/api/ad/replaceAdTemplate'.
Dewhurst identified one of the attackers in Poland, observing attempts to install PHP backdoors to execute system commands. The researcher noted that the attacks appear to exploit the vBulletin vulnerability previously disclosed by Romano, although Nuclei for the vulnerability have been available since May 24, 2025.
It's worth clarifying that Dewhurst only observed attempts to exploit the CVE-2025-48827 vulnerability, with no evidence at this time that attackers have successfully combined it for full remote code execution (RCE) — although this is considered highly likely.
See also: SonicWall SMA1000 vulnerability allows remote access
Based on the above information, it is clear that vBulletin faces serious security risks related to the way it handles PHP in newer versions (such as 8.1). The attacks exploit a combination of vulnerabilities — known as vulnerability chaining — and allow for remote code execution without any authentication, which makes them extremely dangerous.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
