Critical severity9.8OSV Advisory· Published Feb 9, 2018· Updated Jun 17, 2026
CVE-2018-1000059
CVE-2018-1000059
Description
ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
33.0.0, v3.2.10, v3.2.11, …+ 1 more
- (no CPE)range: 3.0.0, v3.2.10, v3.2.11, …
- (no CPE)range: =4.5.4
- cpe:2.3:a:validformbuilder:validform_builder:4.5.4:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/validformbuilder/validformbuilder/issues/126nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.