VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Aug 12, 2020· Updated Jun 17, 2026

CVE-2020-17496

CVE-2020-17496

Description

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Jelsoft/Vbulletin2 versions
    cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*range: >=5.5.4,<=5.6.2
    • (no CPE)range: 5.5.4 - 5.6.2
  • vBulletin/vBulletindescription

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.