Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

vBulletin Remote Code Execution Vulnerability via Crafted subWidgets Data

Vulnerability

A remote code execution vulnerability exists in vBulletin versions 5.5.4 prior to 5.6.2. This issue arises from an incomplete fix for a previous vulnerability (CVE-2019-16759) and allows execution of arbitrary PHP code through manipulated subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.

Impact

Exploitation of this vulnerability allows authenticated users to execute arbitrary PHP code on the server, potentially leading to full compromise of the web application or server.

Reproduction

To reproduce this vulnerability, send a POST request to the '/ajax/render/widget_tabbedcontainer_tab_panel' endpoint. Include 'subWidgets[0][template]' set to 'widget_php' and 'subWidgets[0][config][code]' containing the PHP code to execute. The server will process the request and execute the injected PHP code, returning the output.

Remediation

Users can update to vBulletin versions 5.6.3 or later, where this vulnerability has been patched.

Added: May 15, 2026, 8:58 AM
Updated: May 15, 2026, 8:58 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
7.5
exploitability
10.0
remediation
8.3
relevance
0.0
threat
9.8
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.