← Vulnerability feed

Vulnerability record · CVE-2020-7373 · published 30 October 2020

CVE-2020-7373: vBulletin ajax/render widget subWidgets remote code execution

VVbulletin · Vbulletin

vBulletin 5.5.4 through 5.6.2 allows remote command execution through crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. The flaw is an incomplete fix for CVE-2019-16759 and is a duplicate of CVE-2020-17496, which is the preferred tracking ID. It matters because unauthenticated attackers can execute code on exposed forums.

9.8 CVSS 3.1 Critical EPSS 45% · top 1.3% CWE-94 · Code injection
9.8CVSS 3.1 base score, v2 7.5
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of CVE-2020-17496. CVE-2020-17496 is the preferred CVE ID to track this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, public exploit code, and very high EPSS make this an urgent remote code execution risk.

What it is

vBulletin 5.5.4 through 5.6.2 allows remote command execution through crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. The flaw is an incomplete fix for CVE-2019-16759 and is a duplicate of CVE-2020-17496, which is the preferred tracking ID. It matters because unauthenticated attackers can execute code on exposed forums.

Impact

An attacker can execute arbitrary commands on the server, leading to full compromise of the vBulletin host and any data it holds. No privileges are required.

Attack surface

Reachable over the network via HTTP requests to the ajax/render/widget_tabbedcontainer_tab_panel endpoint. The CVSS vector shows no authentication (PR:N) and no user interaction (UI:N).

Exploitation

Public exploit code and a Metasploit module exist per reference tags, and EPSS is 0.45 (98.7th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade vBulletin to a version that includes the complete fix for CVE-2020-17496 (the preferred CVE for this issue).
  • If immediate upgrade is not possible, restrict or block access to the ajax/render/widget_tabbedcontainer_tab_panel endpoint at the web server or WAF.
  • Apply the vendor security patch referenced in the vBulletin announcement.
  • Monitor for and remove any web shells or unauthorized files left by prior exploitation.
  • Review server logs for suspicious requests to the vulnerable endpoint.

Detection

  • Search HTTP access logs for requests to ajax/render/widget_tabbedcontainer_tab_panel with unusual subWidgets parameters.
  • Monitor for outbound connections or process creation from the web server user that indicate command execution.
  • Use file integrity monitoring on the vBulletin web root to detect newly written files or modifications.
  • Alert on Metasploit or known exploit payload patterns in request bodies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7373 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17496vBulletin ajax render endpoint allows unauthenticated remote command executionvBulletin 5.5.4 through 5.6.2 permits remote command execution through crafted subWidgets data sent to an ajax/render/widget_tabbedcontainer_tab_pane…KEVEPSS 88%analysed9.8CVE-2019-16759vBulletin 5.x widgetConfig code parameter remote code executionvBulletin 5.x through 5.5.4 passes the widgetConfig[code] parameter from an ajax/render/widget_php routestring request into PHP code execution, allow…KEVEPSS 100%analysed9.8CVE-2025-48827vBulletin unauthenticated protected API method invocation on PHP 8.1+vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 on PHP 8.1 or later lets unauthenticated users invoke protected API controller methods, as show…EPSS 76%analysed9.8CVE-2023-25135Vbulletin deserialization of untrusted data vulnerabilityvBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserializati…EPSS 24%9.8CVE-2020-12720vBulletin access control flaw enables unauthenticated SQL injectionvBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 contains incorrect access control that is classified as SQL injection and…EPSS 89%analysed9.8CVE-2019-17132Vbulletin improper input validation vulnerabilityvBulletin through 5.5.4 mishandles custom avatars.EPSS 12%9.8CVE-2017-17671Vbulletin path traversal vulnerabilityvBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can…EPSS 3.1%9.8CVE-2017-17672Vbulletin deserialization of untrusted data vulnerabilityIn vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circum…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2020-7373), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.