CVE-2025-48827Patch(vbulletin / vbulletin)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch vbulletin vbulletin systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-424

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vbulletin

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked at 2 mentions on most recent observed day (2026-04-16)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
vbulletin

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-25: 1Mentions · 2026-04-16: 2Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-04-16: 2Patch / Workaround · 2026-04-16: 2Technical Details · 2026-04-16: 203-2504-16
Signal classification2 categories
Patch
266.7%
Active Exploitation
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-251
Active Exploitation1
2026-04-162
Patch2
Full discourse3 posts
  • Jordano Mazzoni | 🌩 #Cloud 🛡️#Cybersecurity #AWS@jordano_mazzoni
    Patch

    🔍 Attention, security professionals! New critical CVEs require immediate action: CVE-2026-20963 (SharePoint) – RCE via deserialization CVE-2025-48827 (vBulletin) – CVSS 10.0, actively exploited CVE-2025-70401/70400 (UniFi) – Path traversal and RCE with network access CVE-2023-43010 (Apple) – Memory corruption in Safari and iOS ✅ Stay up to date. 🛠️ Patches are now available. 🚨 Real threats, urgent response. #Cybersecurity #CVE #InfoSec #CISAKEV #PatchNow

    Post summary

    The text announces several critical CVEs, notes active exploitation for at least one, and stresses that patches are available, urging immediate action.

    01030122
    3.2K followersView on X
  • Jordano Mazzoni | 🌩 #Cloud 🛡️#Cybersecurity #AWS@jordano_mazzoni
    Patch

    🔍 セキュリティ専門家の皆様、注意してください! 新しい重要な CVE には即時の対応が必要です。 CVE-2026-20963 (SharePoint) – 逆シリアル化による RCE CVE-2025-48827 (vBulletin) – CVSS 10.0、積極的に悪用されています CVE-2025-70401/70400 (UniFi) – ネットワーク アクセスによるパス トラバーサルと RCE CVE-2023-43010 (Apple) – Safari および iOS でのメモリ破損 ✅ 最新情報を入手してください。 🛠️ パッチが利用可能になりました。 🚨 本当の脅威、緊急対応。 #サイバーセキュリティ #CVE #情報セキュリティ #CISAKEV #今すぐパッチ

    Post summary

    The post alerts on multiple critical CVEs, notes active exploitation of at least one, and confirms patches are now available, urging immediate action.

    0001037
    2.9K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    Experts found two vulnerabilities in the vBulletin forum software, one of which is already being exploited in real-world attacks. Two critical vBulletin flaws, tracked as CVE-2025-48827 and CVE-2025-48828, enable API ab... https://f.mtr.cool/pnbwgefadm

    Post summary

    Two critical vBulletin flaws (CVE-2025-48827 and CVE-2025-48828) have been discovered, with one already being actively exploited in real‑world attacks.

    01000187
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvbulletinvbulletin---

Explore more