peter bassill · operator
$ cve CVE-2025-48827 JSON

CVE-2025-48827

10.0
CRITICAL · CVSS 3.1 · EPSS 75.8% (pctl 100)

Patch early

EPSS 75.8% — above the 10% action threshold.

Description

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS75.84% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-424
On CISA KEVno
Public exploitnone known
Published2025-05-27
Last modified2026-06-17

Affected (1)

VendorProduct
vbulletinvbulletin

References

→ the Explorer  ·  watch your stack  ·  NVD