vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVbulletin
APPVbulletin5.0.0 – 5.5.4
CISA KEV — detailsi
- Vendori
- vBulletin
- Producti
- vBulletin
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 3 maja 2022
References
Related vulnerabilities
CVE-2020-17496CRITICAL9.8⚠ KEVPL ✓same product
vBulletin 5.x — zdalne wykonanie kodu (RCE) przez subWidgets
CVE-2025-48828CRITICAL9.0PL ✓same product
RCE w vBulletin poprzez Template Conditionals — wykonanie dowolnego kodu PHP
CVE-2025-48827CRITICAL10.0PL ✓same product
vBulletin — nieautoryzowany dostęp do chronionych metod API (RCE)
CVE-2023-25135CRITICAL9.8PL ✓same product
vBulletin RCE przez deserializację bez uwierzytelnienia (pre-5.6.9 PL1)
CVE-2020-7373CRITICAL9.8PL ✓same product
vBulletin 5.5.4–5.6.2: RCE przez niekompletną łatę CVE-2019-16759