← Vulnerability feed

Vulnerability record · CVE-2015-7808 · published 24 November 2015

CVE-2015-7808: vBulletin 5 Connect PHP object injection in decodeArguments

VVbulletin · Vbulletin

The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 fails to validate the arguments parameter, allowing PHP object injection. A crafted serialized object sent to ajax/api/hook/decodeArguments can lead to arbitrary PHP code execution on the server.

7.5 CVSS 2.0 High EPSS 81% · top 0.4% CWE-20 · Improper input validation
7.5CVSS 2.0 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 12 tagged exploit
17 Jun 2026Last modified by NVD

Description

The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with public exploits and in-the-wild activity, despite not being in CISA KEV.

What it is

The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 fails to validate the arguments parameter, allowing PHP object injection. A crafted serialized object sent to ajax/api/hook/decodeArguments can lead to arbitrary PHP code execution on the server.

Impact

A remote attacker can execute arbitrary PHP code on the vBulletin server, leading to full compromise of the web application and its data.

Attack surface

Reachable over the network via HTTP requests to ajax/api/hook/decodeArguments; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.

Exploitation

Multiple public exploit references exist, including a Check Point 0-day disclosure and in-the-wild reports; EPSS is 0.80635 (99.6th percentile), but CISA KEV does not list it.

What to do

  • Upgrade vBulletin 5 Connect to a version later than 5.1.9 that fixes the decodeArguments unserialization flaw.
  • If immediate upgrade is not possible, restrict or block access to ajax/api/hook/decodeArguments at the web server or WAF.
  • Apply vendor patches or hotfixes as soon as they are available.
  • Monitor for and remove any webshells or unexpected PHP files that may have been placed after exploitation.

Detection

  • Inspect HTTP requests for POST parameters named arguments containing serialized PHP object strings (e.g., O: or a: patterns) to ajax/api/hook/decodeArguments.
  • Monitor web server logs for requests to ajax/api/hook/decodeArguments with unusual or malformed arguments.
  • Use file integrity monitoring to detect new or modified PHP files in the web root.
  • Review PHP error logs for unserialize warnings or object injection errors.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-7808 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17496vBulletin ajax render endpoint allows unauthenticated remote command executionvBulletin 5.5.4 through 5.6.2 permits remote command execution through crafted subWidgets data sent to an ajax/render/widget_tabbedcontainer_tab_pane…KEVEPSS 88%analysed9.8CVE-2019-16759vBulletin 5.x widgetConfig code parameter remote code executionvBulletin 5.x through 5.5.4 passes the widgetConfig[code] parameter from an ajax/render/widget_php routestring request into PHP code execution, allow…KEVEPSS 100%analysed9.8CVE-2025-48827vBulletin unauthenticated protected API method invocation on PHP 8.1+vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 on PHP 8.1 or later lets unauthenticated users invoke protected API controller methods, as show…EPSS 76%analysed9.8CVE-2023-25135Vbulletin deserialization of untrusted data vulnerabilityvBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserializati…EPSS 24%9.8CVE-2020-7373vBulletin ajax/render widget subWidgets remote code executionvBulletin 5.5.4 through 5.6.2 allows remote command execution through crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel requ…EPSS 45%analysed9.8CVE-2020-12720vBulletin access control flaw enables unauthenticated SQL injectionvBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 contains incorrect access control that is classified as SQL injection and…EPSS 89%analysed9.8CVE-2019-17132Vbulletin improper input validation vulnerabilityvBulletin through 5.5.4 mishandles custom avatars.EPSS 12%9.8CVE-2017-17671Vbulletin path traversal vulnerabilityvBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2015-7808), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.