← Vulnerability feed

Vulnerability record · CVE-2019-16759 · published 24 September 2019

CVE-2019-16759: vBulletin 5.x widgetConfig code parameter remote code execution

VVbulletin · Vbulletin

vBulletin 5.x through 5.5.4 passes the widgetConfig[code] parameter from an ajax/render/widget_php routestring request into PHP code execution, allowing remote command execution. The flaw is pre-authentication and trivially reachable, so any exposed vulnerable forum is at immediate risk. It is listed in CISA KEV and has public exploit code, making it a high-value target for mass scanning.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 100% · top 0.1% CWE-94 · Code injection
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
21References, 18 tagged exploit
17 Jun 2026Last modified by NVD

Description

vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with public exploit code, KEV listing, and near-certain EPSS probability makes this an urgent patch-or-mitigate case.

What it is

vBulletin 5.x through 5.5.4 passes the widgetConfig[code] parameter from an ajax/render/widget_php routestring request into PHP code execution, allowing remote command execution. The flaw is pre-authentication and trivially reachable, so any exposed vulnerable forum is at immediate risk. It is listed in CISA KEV and has public exploit code, making it a high-value target for mass scanning.

Impact

An unauthenticated attacker can execute arbitrary commands on the web server, leading to full compromise of the vBulletin host and any data or credentials it holds. This can be used for webshell deployment, data theft, or lateral movement into the hosting environment.

Attack surface

Reached over the network via an HTTP request to the ajax/render/widget_php endpoint with a crafted widgetConfig[code] parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Exploitation is confirmed and active: the CVE is in CISA KEV (added 2021-11-03), EPSS 30-day probability is 0.99728 (99.95th percentile), and multiple references are tagged Exploit, including public pre-auth RCE write-ups and media coverage of mass attacks.

What to do

  • Upgrade vBulletin to a version later than 5.5.4 per vendor instructions; this is the only complete fix.
  • If immediate patching is not possible, block or restrict access to the ajax/render/widget_php route at the WAF or reverse proxy.
  • Remove or disable the PHP widget module if it is not required for site functionality.
  • Isolate the vBulletin host from internal networks and limit outbound traffic to reduce post-exploitation impact.
  • Rotate database, admin, and server credentials after confirming a clean state.

Detection

  • Search web logs for requests to ajax/render/widget_php containing widgetConfig[code] or routestring parameters.
  • Monitor for unexpected PHP processes, webshell files, or outbound connections originating from the vBulletin server.
  • Alert on POST requests to ajax/render endpoints from IPs with no prior session or authentication.
  • Review file integrity on the vBulletin webroot for modified or newly created PHP files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-16759 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "vBulletin PHP Module Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154648/vBulletin-5.x-Pre-Auth-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155633/vBulletin-5.5.4-Remote-Command-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158829/vBulletin-5.x-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158830/vBulletin-5.x-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158866/vBulletin-5.x-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2020/Aug/5 ExploitMailing ListThird Party Advisory
https://arstechnica.com/information-technology/2019/09/public-exploit-code-spawns-mass-attacks-against-high-severity-vbu ExploitPress/Media CoverageThird Party Advisory
https://seclists.org/fulldisclosure/2019/Sep/31 ExploitMailing ListThird Party Advisory
https://www.theregister.co.uk/2019/09/24/vbulletin_vbug_zeroday/ Press/Media CoverageThird Party Advisory
http://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154648/vBulletin-5.x-Pre-Auth-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155633/vBulletin-5.5.4-Remote-Command-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158829/vBulletin-5.x-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158830/vBulletin-5.x-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158866/vBulletin-5.x-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2020/Aug/5 ExploitMailing ListThird Party Advisory
https://arstechnica.com/information-technology/2019/09/public-exploit-code-spawns-mass-attacks-against-high-severity-vbu ExploitPress/Media CoverageThird Party Advisory
https://seclists.org/fulldisclosure/2019/Sep/31 ExploitMailing ListThird Party Advisory
https://www.theregister.co.uk/2019/09/24/vbulletin_vbug_zeroday/ Press/Media CoverageThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16759 US Government Resource

Track CVE-2019-16759 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17496vBulletin ajax render endpoint allows unauthenticated remote command executionvBulletin 5.5.4 through 5.6.2 permits remote command execution through crafted subWidgets data sent to an ajax/render/widget_tabbedcontainer_tab_pane…KEVEPSS 88%analysed9.8CVE-2025-48827vBulletin unauthenticated protected API method invocation on PHP 8.1+vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 on PHP 8.1 or later lets unauthenticated users invoke protected API controller methods, as show…EPSS 76%analysed9.8CVE-2023-25135Vbulletin deserialization of untrusted data vulnerabilityvBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserializati…EPSS 24%9.8CVE-2020-7373vBulletin ajax/render widget subWidgets remote code executionvBulletin 5.5.4 through 5.6.2 allows remote command execution through crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel requ…EPSS 45%analysed9.8CVE-2020-12720vBulletin access control flaw enables unauthenticated SQL injectionvBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 contains incorrect access control that is classified as SQL injection and…EPSS 89%analysed9.8CVE-2019-17132Vbulletin improper input validation vulnerabilityvBulletin through 5.5.4 mishandles custom avatars.EPSS 12%9.8CVE-2017-17671Vbulletin path traversal vulnerabilityvBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can…EPSS 3.1%9.8CVE-2017-17672Vbulletin deserialization of untrusted data vulnerabilityIn vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circum…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2019-16759), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.