VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Sep 24, 2019· Updated Jun 17, 2026

CVE-2019-16759

CVE-2019-16759

Description

vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Jelsoft/Vbulletin2 versions
    cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*range: >=5.0.0,<=5.5.4
    • (no CPE)range: 5.x through 5.5.4
  • vBulletin/vBulletindescription

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.