CVE-2016-6175: PHP-Gettext Project PHP-Gettext

Critical severity, CVSS 9.8. EPSS: 19.7% chance of exploitation in the next 30 days.

Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.

Affected products

Published 2017-02-07. Last modified 2026-06-17.