Skip to content
COOEY

FAIL › dossier

vBulletin

VENDOR

· dossier confidence 50%

vBulletin is a forum software vendor with a documented history of high-severity remote code execution vulnerabilities in its PHP modules, particularly around widget configuration and rendering. The vendor's security posture is characterized by repeated critical flaws that require active patching and monitoring.

PROFILE
Categorysoftware vendorWhat they dovBulletin is a forum software platform used for building online communities and discussion boards.
SECURITY POSTURE

The vendor has a poor security track record, with multiple high-severity remote code execution (RCE) vulnerabilities discovered in its PHP modules within a single year, indicating systemic issues in input validation and secure coding practices.

Notable failures
  • CVE-2020-17496 RCE via subWidgets data
  • CVE-2019-16759 RCE via widgetConfig parameter
Patterns: repeated unpatched RCE vulnerabilities in PHP modules; lack of input validation on widget configuration parameters
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2019-16759 high vBulletin's PHP module allowed remote code execution via an unvalidated widget configuration parameter, enabling attackers to inject arbitrary code into forum instances.
2021-11-03 CVE-2019-16759 high vBulletin's PHP module allowed remote code execution via an unvalidated widget configuration parameter, enabling attackers to inject arbitrary code into forum instances.
2021-11-03 CVE-2020-17496 high vBulletin's PHP module allowed remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.
2021-11-03 CVE-2020-17496 high vBulletin's PHP module allowed remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
CISA KEV listing signals active exploitation, indicating severe fallout for vBulletin despite lack of explicit press condemnation in provided sources.
synthesissevere-fallout-0.60
CVE-2019-16759 is a critical RCE vulnerability in vBulletin's PHP module, allowing remote code execution via the widgetConfig parameter. The lack of timely patching or public acknowledgment of the sev
socradar.io ↗severe-fallout-0.60
Neutral/Technical
"CVE-2020-17496 vBulletin PHP Module Remote Code Execution Vulnerability vBulletin 5.5.4 through 5.6"
CISA ↗severe-fallout-0.60
Neutral/Technical
"CISA Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
cvefeed.io ↗severe-fallout-0.60
Neutral/Technical
"CVEFeed.io mirrors every entry, joins it to full CVE and severity data, and tracks new additions so you can prioritize remediation the moment a vulnerability enters the catalog."
www.cvefind.com ↗severe-fallout-0.60
Neutral/Technical
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
kev.5sn.com ↗severe-fallout-0.60
Neutral/Technical
"CVE-2020-17496 vBulletin PHP Module Remote Code Execution Vulnerability vBulletin 5.5.4 through 5.6"
NVD ↗severe-fallout-0.60
Neutral/Technical
"NVD - Vulnerabilities"
tech-insider.org ↗severe-fallout+0.00
Neutral; Tech Insider article discusses a different 2026 Klue data breach and offers no commentary on vBulletin or CVE-2019-16759.
cooey ↗severe-fallout-0.80
Severe fallout; NVD entry confirms critical RCE vulnerability in vBulletin's PHP module, allowing remote code execution via the widgetConfig parameter, indicating a severe security failure.
"The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request."
NVD ↗severe-fallout+0.00
Neutral; NVD home page provides no specific commentary on vBulletin or CVE-2019-16759.
www.cvefind.com ↗severe-fallout+0.00
Neutral; CVE Find database page lists CVEs but offers no specific commentary on vBulletin or CVE-2019-16759.
NIST ↗severe-fallout+0.00
Neutral; NIST NVD home page provides no specific commentary on vBulletin or CVE-2019-16759.
CISA ↗severe-fallout+0.00
Neutral; CISA KEV catalog page lists known exploited vulnerabilities but offers no specific commentary on vBulletin or CVE-2019-16759.
vulners.com ↗severe-fallout+0.00
Neutral; Vulners.com vulnerability intelligence platform page provides no specific commentary on vBulletin or CVE-2019-16759.
cooey ↗severe-fallout-0.60
Neutral/Technical
"The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759."
Open questions: What is the exact founding year of vBulletin? · What is the current headquarters location of vBulletin? · What is the current ownership structure of vBulletin? · What is the current size of vBulletin's workforce?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-18 04:00:58.241860+00:00