CVE-2018-1000059
CRITICALValidFormBuilder 4.5.4 - Code Injection
Title source: llmDescription
ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.
Scores
CVSS v3
9.8
EPSS
0.0027
EPSS Percentile
49.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
validformbuilder/validform_builder
Timeline
Published
Feb 09, 2018
Tracked Since
Feb 18, 2026