CVE-2017-9080: PlaySMS

High severity, CVSS 8.8. EPSS: 62.3% chance of exploitation in the next 30 days.

PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.

Affected products

Published 2017-05-19. Last modified 2026-06-17.