CVE-2016-5726: Simplemachines Simple Machines Forum
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
Affected products
- Simplemachines Simple Machines Forum: version 2.1 only
Published 2017-02-09. Last modified 2026-06-17.