Skip to content
COOEY

EXPOSURES › CVE-2019-16759

CVE-2019-16759

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-16759 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

vBulletin's PHP module allowed remote code execution via an unvalidated widget configuration parameter, enabling attackers to inject arbitrary code into forum instances.

The vulnerability in vBulletin's PHP module allowed remote code execution through the widgetConfig[code] parameter, letting attackers inject malicious code into forum pages. DIB organizations must ensure their forum software is patched and monitored, as unpatched RCE flaws are common entry points for ransomware and data breaches. The vendor's repeated critical flaws indicate systemic input validation issues that require active patching and monitoring.

Shame score — The flaw was actively exploited in the wild (KEV) and represents a repeated critical failure in input validation and secure coding practices by a vendor with a poor security track record.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
CVE-2019-16759 is a critical RCE vulnerability in vBulletin's PHP module, allowing remote code execution via the widgetConfig parameter. The lack of timely patching or public acknowledgment of the sev
cooey ↗ severe-fallout -0.80
Severe fallout; NVD entry confirms critical RCE vulnerability in vBulletin's PHP module, allowing remote code execution via the widgetConfig parameter, indicating a severe security failure.
"The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request."
NVD ↗ severe-fallout +0.00
Neutral; NVD home page provides no specific commentary on vBulletin or CVE-2019-16759.
www.cvefind.com ↗ severe-fallout +0.00
Neutral; CVE Find database page lists CVEs but offers no specific commentary on vBulletin or CVE-2019-16759.
NIST ↗ severe-fallout +0.00
Neutral; NIST NVD home page provides no specific commentary on vBulletin or CVE-2019-16759.
CISA ↗ severe-fallout +0.00
Neutral; CISA KEV catalog page lists known exploited vulnerabilities but offers no specific commentary on vBulletin or CVE-2019-16759.
vulners.com ↗ severe-fallout +0.00
Neutral; Vulners.com vulnerability intelligence platform page provides no specific commentary on vBulletin or CVE-2019-16759.
tech-insider.org ↗ severe-fallout +0.00
Neutral; Tech Insider article discusses a different 2026 Klue data breach and offers no commentary on vBulletin or CVE-2019-16759.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.