CVE-2019-10774: PHP-Shellcommand Project PHP-Shellcommand
Critical severity, CVSS 9.8. EPSS: 4.6% chance of exploitation in the next 30 days.
php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected products
- PHP-Shellcommand Project PHP-Shellcommand: before 1.6.1 (fixed in 1.6.1)
Published 2019-12-30. Last modified 2026-06-17.