References https://nvd.nist.gov/vuln/detail/CVE-2019-16759 https://www.cve.org/CVERecord?id=CVE-2019-16759 https://unit42.paloaltonetworks.com/exploits-in-the-wild-for-vbulletin-pre-auth-rce-vulnerability-cve-2019-16759/ https://blog.cloudflare.com/cloudflares-protection-against-a-new-remote-code-execution-vulnerability-cve-2019-16759-in-vbulletin/ https://seclists.org/fulldisclosure/2019/Sep/31 https://www.exploit-db.com/exploits/47437 https://github.com/ludy-dev/vBulletin_Routestring-RCE https://www.secpod.com/blog/vbulletin-remote-code-execution-vulnerability-cve-2019-16759/ https://nsfocusglobal.com/vbulletin-remote-code-execution-vulnerability-cve-2019-16759-threat-alert/ https://medium.com/@sinfulz/cve-2019-16759-demonstration-d764ac7737e2
Related VulnerabilitiesPoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codePoCCVE-2026-2113: tpadmin <= 1.3.12 - Remote Code ExecutionPoCCVE-2026-21875: ClipBucket v5 <= 5.5.2 - Unauthenticated Blind SQL InjectionPoCCVE-2026-34234: CtrlPanel <= 1.1.1 - Remote Code ExecutionPoCCVE-2026-41679: Paperclip - Remote Code ExecutionPoCCVE-2026-5562: Provectus kafka-ui <=0.7.2 - Remote Code ExecutionPoCCVE-2026-58123: Hermes WebUI < 0.51.788 - Remote Code ExecutionPoCCVE-2026-82222: GiveWP <= 4.16.7.1 - Remote Code ExecutionPoCCVE-2026-41042: Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution綠色運算|NUMail - OS Command InjectionPoCCVE-2026-40217: LiteLLM < 1.25.0 - Remote Code ExecutionPoCCVE-2026-45695: Kopia Server 0.23.0 - Remote Code ExecutionPoCCVE-2026-61511: vBulletin 6.x - Remote Code Execution