{"id":"CVE-2019-16759","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-16759","summary":"vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.","details":"vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.","published":"2019-09-24T22:15:13.183","modified":"2026-06-17T02:22:44.363","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.99728,"percentile":0.99952,"asOf":"2026-08-25"},"cisaKev":{"dateAdded":"2021-11-03","dueDate":"2022-05-03","knownRansomwareCampaignUse":false},"exploitsKnown":30,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/154648/vBulletin-5.x-Pre-Auth-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/155633/vBulletin-5.5.4-Remote-Command-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/158829/vBulletin-5.x-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/158830/vBulletin-5.x-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/158866/vBulletin-5.x-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"http://seclists.org/fulldisclosure/2020/Aug/5"},{"type":"EXPLOIT","url":"https://arstechnica.com/information-technology/2019/09/public-exploit-code-spawns-mass-attacks-against-high-severity-vbulletin-bug/"},{"type":"EXPLOIT","url":"https://seclists.org/fulldisclosure/2019/Sep/31"},{"type":"ADVISORY","url":"https://www.theregister.co.uk/2019/09/24/vbulletin_vbug_zeroday/"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/154648/vBulletin-5.x-Pre-Auth-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/155633/vBulletin-5.5.4-Remote-Command-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/158829/vBulletin-5.x-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/158830/vBulletin-5.x-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/158866/vBulletin-5.x-Remote-Code-Execution.html"},{"type":"EXPLOIT","url":"http://seclists.org/fulldisclosure/2020/Aug/5"},{"type":"EXPLOIT","url":"https://arstechnica.com/information-technology/2019/09/public-exploit-code-spawns-mass-attacks-against-high-severity-vbulletin-bug/"},{"type":"EXPLOIT","url":"https://seclists.org/fulldisclosure/2019/Sep/31"},{"type":"ADVISORY","url":"https://www.theregister.co.uk/2019/09/24/vbulletin_vbug_zeroday/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16759"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T02:22:44.363"}}