CVE-2018-1000059: Validformbuilder Validform Builder

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.

Affected products

Published 2018-02-09. Last modified 2026-06-17.