CVE-2016-5727: Simplemachines Simple Machines Forum
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
Affected products
- Simplemachines Simple Machines Forum: version 2.1 only
Published 2017-02-09. Last modified 2026-06-17.