← Back to CVE List
Vulnerability Intelligence Report

CVE-2023-25135

vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors. The fixed versions are 5.6.7 PL1, 5.6.8 PL1, and 5.6.9 PL1.

Nuclei Template
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:23.93%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-502 ↗CWE-502 Deserialization of Untrusted Data

Affected Products & Versions

Vendor Product Affected Versions
vbulletin vbulletin 5.6.7, 5.6.8, 5.6.9

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
23.926%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2023-02-03T00:00:00
Published2023-02-03T00:00:00
Last Updated2025-03-26T14:52:17

LINK COPIED TO CLIPBOARD