References https://github.com/jas502n/CVE-2019-16759 https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/vBulletin/%EF%BC%88CVE-2019-16759%EF%BC%89vBulletin%205.x%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://nosec.org/m/share/4557.html https://avd.aliyun.com/product?prod=vbulletin https://blog.nsfocus.net/vbulletin-5-rce-vulnerability/ https://zhuanlan.zhihu.com/p/32183957 https://www.secrss.com/articles/13954 https://www.ddpoc.com/DVB-2021-2097.html http://nic.cqrk.edu.cn/2020_08/11_11/content-16141.html https://stack.chaitin.com/vuldb/detail/a41dbdac-678e-40bb-ab45-0e608713cf21 https://blog.csdn.net/WangsuSecurity/article/details/134698601 https://disk.scan.cm/All_wiki/yougar0.github.io%28%E5%9F%BA%E4%BA%8E%E9%9B%B6%E7%BB%84%E5%85%AC%E5%BC%80%E6%BC%8F%E6%B4%9E%E5%BA%93%20%2B%20PeiQi%E6%96%87%E5%BA%93%E7%9A%84%E4%B8%80%E4%BA%9B%E6%BC%8F%E6%B4%9E%29-10715/Web%E5%AE%89%E5%85%A8/vBulletin/%EF%BC%88CVE-2015-7808%EF%BC%89VBulletin%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md?hash=zE0KEPGJ https://www.anquanke.com/post/id/146416 https://www.ichunqiu.com/course/60507 https://www.cnvd.org.cn/patchInfo/show/184465 https://unit42.paloaltonetworks.com/cve-2020-17496/ https://www.sentinelone.com/blog/vbulletin-cve-2023-25135/ https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=34160 https://www.secpod.com/blog/vbulletin-remote-code-execution-vulnerability-cve-2019-16759/ https://nvd.nist.gov/vuln/detail/cve-2019-16759 https://nvd.nist.gov/vuln/detail/cve-2020-17496 https://nvd.nist.gov/vuln/detail/cve-2023-25135 https://nvd.nist.gov/vuln/detail/cve-2025-48827 https://nvd.nist.gov/vuln/detail/cve-2025-48828 https://app.opencve.io/cve/?vendor=vbulletin&product=vbulletin&page=1 https://www.anquanfuwu.net/article/detail/68382e1a14037f0e4935dedf
Related VulnerabilitiesPoCCVE-2026-61511: vBulletin 6.x - Remote Code ExecutionvBulletin /ajax/render/pagenav 代码执行漏洞(CVE-2026-61511)CVE-2019-16759: vBulletin v5.0.0-v5.5.4 Remote Command ExecutionPoCCVE-2016-6195: vBulletin <= 4.2.3 - SQL InjectionPoCCVE-2018-6200: vBulletin - Open RedirectPoCCVE-2019-16759: vBulletin 5.0.0-5.5.4 - Remote Command ExecutionPoCCVE-2020-12720: vBulletin SQL InjectionPoCCVE-2020-17496: vBulletin 5.5.4 - 5.6.2- Remote Command ExecutionPoCCVE-2023-25135: vBulletin <= 5.6.9 - Pre-authentication Remote Code ExecutionPoCCVE-2025-48827: vBulletin 5.0.0-6.0.3 - Authentication BypassPoCCVE-2025-48828: vBulletin replaceAdTemplate - Remote Code ExecutionPoCvbulletin-ajaxreg-sqli: vBulletin 3.x / 4.x AjaxReg - SQL InjectionPoCvbulletin-backdoor: vBulletin Backdoor - Detect