Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code.
CVE ID: CVE-2025-48828
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.0
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vendor: vBulletin
Product: vBulletin
EPSS Score: 10.71% (probability of being exploited)
EPSS Percentile: 92.93% (scored less or equal to compared to others)
EPSS Date: 2025-06-06 (when was this score calculated)