Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-112973. PoCs published by mc2_s3lector.
AI-analyzed exploit summary This exploit demonstrates a code execution vulnerability in vBulletin 4.0.4 via manipulation of the 'comma' parameter in forumdisplay.php, allowing arbitrary command execution. It also references a potential JavaScript injection via vbulletin-core.js.
Description
vbbuletin 4.0.4 - Multiple Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
by mc2_s3lector · textwebappsphp
https://www.exploit-db.com/exploits/14686
This exploit demonstrates a code execution vulnerability in vBulletin 4.0.4 via manipulation of the 'comma' parameter in forumdisplay.php, allowing arbitrary command execution. It also references a potential JavaScript injection via vbulletin-core.js.
Classification
Working Poc 80%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
vBulletin 4.0.4
No auth needed
Prerequisites:
Access to the target vBulletin instance · vBulletin 4.0.4 installed
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026