CVE-2019-16759
KEVCRITICAL 9.8EPSS 99.7%
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 99.73% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03
- Nuclei
- critical · CWE-94
- Published
- 2019-09-24
- Updated
- 2025-10-21
Proof-of-concept exploits (24)
- http://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-E…
- http://packetstormsecurity.com/files/154648/vBulletin-5.x-Pre-Auth-Remote-Code-Execution.…
- http://packetstormsecurity.com/files/155633/vBulletin-5.5.4-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/158829/vBulletin-5.x-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/158830/vBulletin-5.x-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/158866/vBulletin-5.x-Remote-Code-Execution.html
- https://seclists.org/fulldisclosure/2019/Sep/31
- https://arstechnica.com/information-technology/2019/09/public-exploit-code-spawns-mass-at…
- 0xdims/CVE-2019-167596★ · 2020-08-16
- FarjaalAhmad/CVE-2019-167594★ · 2019-10-12
- M0sterHxck/CVE-2019-16759-Vbulletin-rce-exploit5★ · 2023-05-26
- andripwn/pwn-vbulletin4★ · 2020-09-20
- cotrufo/makura1★ · 2023-01-01
- fxp0-4tx/CVE-2019-167590★ · 2020-09-06
- huyanshuhan/NekoBotV10★ · 2020-02-08
- jas502n/CVE-2019-1675921★ · 2019-09-26
- ludy-dev/vBulletin_Routestring-RCE1★ · 2020-11-07
- mas1337/CVE-2019-167596★ · 2020-08-16
- nako48/CVE-2019-167591★ · 2020-09-02
- p0megranate/makura1★ · 2023-01-01
- polar1s7/CVE-2019-16759-bypass0★ · 2020-08-12
- psychoxploit/vbull0★ · 2020-02-29
- r00tpgp/http-vuln-CVE-2019-167593★ · 2019-09-26
- sunian19/CVE-2019-167591★ · 2020-08-24
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (2)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/vbulletin-cve-2019-16759.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2019/CVE-2019-16759.yaml