CVE-2025-48827
Unauthorized API Access in vBulletin 5.x/6.x on PHP

Publication date: 2025-05-27

Last updated on: 2025-06-25

Assigner: [email protected]

Description
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Affected Vendors & Products
Vendor Product Version
vbulletin vbulletin *
vbulletin vbulletin *
vbulletin vbulletin *
vbulletin vbulletin *
vbulletin vbulletin From 5.0.0 (inc) to 5.7.5 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-424
AI Powered Q&A
Can you explain this vulnerability to me?


How can this vulnerability impact me? :


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
Meta Information
CVE Publication Date:
2025-05-27
CVE Last Modified Date:
2025-06-25
Report Generation Date:
2025-06-27
AI Powered Q&A Generation:
2025-05-28
EPSS Last Evaluated Date:
2025-06-03
NVD Report Link: