VYPR

Smf2.1

by Simple Machines

Source repositories

CVEs (2)

  • CVE-2016-5727HigFeb 9, 2017
    risk 0.57cvss 8.8epss 0.02

    LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.

  • CVE-2013-7467MedMar 7, 2019
    risk 0.40cvss 6.1epss 0.01

    Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.