CVE-2019-11574: Simplemachines Simple Machine Forum

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.

Affected products

Published 2020-03-20. Last modified 2026-06-17.