CVE-2025-48827: vBulletin

Critical severity, CVSS 9.8. EPSS: 75.8% chance of exploitation in the next 30 days.

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.

Affected products

  • vBulletin vBulletin: from 5.0.0, up to and including 5.7.5; from 6.0.0, up to and including 6.0.3

Published 2025-05-27. Last modified 2026-06-17.