CVE-2016-5726: Simplemachines Simple Machines Forum

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.

Affected products

Published 2017-02-09. Last modified 2026-06-17.