References https://blog.nsfocus.net/vbulletin-5-rce-vulnerability/ https://www.anquanke.com/post/id/82870 https://tttang.com/archive/109/ https://juejin.cn/post/6844903572484653063 https://qkl.seebug.org/vuldb/ssvid-89707 https://github.com/jas502n/CVE-2019-16759 https://avd.aliyun.com/product?prod=vbulletin https://www.wangsu.com/news/content/blog/3617 https://www.ctfiot.com/110824.html https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/vBulletin/%EF%BC%88CVE-2019-16759%EF%BC%89vBulletin%205.x%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/
Related VulnerabilitiesPoCCVE-2026-61511: vBulletin 6.x - Remote Code ExecutionvBulletin /ajax/render/pagenav 代码执行漏洞(CVE-2026-61511)CVE-2019-16759: vBulletin v5.0.0-v5.5.4 Remote Command ExecutionPoCCVE-2016-6195: vBulletin <= 4.2.3 - SQL InjectionPoCCVE-2018-6200: vBulletin - Open RedirectPoCCVE-2019-16759: vBulletin 5.0.0-5.5.4 - Remote Command ExecutionPoCCVE-2020-12720: vBulletin SQL InjectionPoCCVE-2020-17496: vBulletin 5.5.4 - 5.6.2- Remote Command ExecutionPoCCVE-2023-25135: vBulletin <= 5.6.9 - Pre-authentication Remote Code ExecutionPoCCVE-2025-48827: vBulletin 5.0.0-6.0.3 - Authentication BypassPoCCVE-2025-48828: vBulletin replaceAdTemplate - Remote Code ExecutionPoCvbulletin-ajaxreg-sqli: vBulletin 3.x / 4.x AjaxReg - SQL InjectionPoCvbulletin-backdoor: vBulletin Backdoor - Detect