started · updated
NodeBB and vBulletin Forum Software Vulnerabilities Put Users at Risk
Security researchers have identified eight high‑severity vulnerabilities in NodeBB, a popular Node.js‑based forum platform. The flaws, affecting all versions prior to 4.14.0, include three cross‑site scripting issues, authorization‑bypass weaknesses and a chain that can reveal private messages or allow full forum takeover. The bugs were uncovered during an AI‑assisted white‑box penetration test conducted by the firm Aikido.
A separate, unrelated flaw was disclosed in vBulletin software. An unauthenticated request can trigger PHP's eval() function in the template engine, enabling remote code execution on unpatched installations. The issue, catalogued as CVE‑2026‑61511, affects vBulletin 6.2.1 and earlier versions. Patches were issued at the end of June, and a public exploit was released on July 27, though no active exploitation has been reported.
Administrators of both platforms are urged to upgrade to the latest patched versions—NodeBB 4.14.0 or later and vBulletin 6.2.2—to mitigate the risk of compromise.
Entities
Aikido · CVE‑2026‑61511 · NodeBB · vBulletin