August 10, 2026

CVE Watchtower


← Back to CVE List

CVE-2019-16759NVD

Vulnerability Summary

vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Severity Level
UNKNOWN
Published Date
Sep 24, 2019
Last Modified
Oct 21, 2025
Exploitation Status
ACTIVE
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A