References https://nvd.nist.gov/vuln/detail/CVE-2023-25135 https://www.sentinelone.com/blog/vbulletin-cve-2023-25135/ https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=34160 https://www.ambionics.io/blog/vbulletin-unserializable-but-unreachable https://avd.aliyun.com/detail?id=AVD-2023-25135 https://www.ctfiot.com/110824.html https://www.ddpoc.com/DVB-2023-4315.html https://blog.csdn.net/WangsuSecurity/article/details/134698601 https://github.com/ambionics/vbulletin-exploits/blob/main/vbulletin-rce-cve-2023-25135.py https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-25135.yaml
Related VulnerabilitiesPoCCVE-2026-61511: vBulletin 6.x - Remote Code ExecutionvBulletin /ajax/render/pagenav 代码执行漏洞(CVE-2026-61511)CVE-2019-16759: vBulletin v5.0.0-v5.5.4 Remote Command ExecutionPoCCVE-2016-6195: vBulletin <= 4.2.3 - SQL InjectionPoCCVE-2018-6200: vBulletin - Open RedirectPoCCVE-2019-16759: vBulletin 5.0.0-5.5.4 - Remote Command ExecutionPoCCVE-2020-12720: vBulletin SQL InjectionPoCCVE-2020-17496: vBulletin 5.5.4 - 5.6.2- Remote Command ExecutionPoCCVE-2023-25135: vBulletin <= 5.6.9 - Pre-authentication Remote Code ExecutionPoCCVE-2025-48827: vBulletin 5.0.0-6.0.3 - Authentication BypassPoCCVE-2025-48828: vBulletin replaceAdTemplate - Remote Code ExecutionPoCvbulletin-ajaxreg-sqli: vBulletin 3.x / 4.x AjaxReg - SQL InjectionPoCvbulletin-backdoor: vBulletin Backdoor - Detect