{"id":"CVE-2016-5726","details":"Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.","modified":"2026-08-07T14:31:43.845386Z","published":"2017-02-09T15:59:01.127Z","references":[{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/06/10/7"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/06/18/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/simplemachines/smf","events":[{"introduced":"453cbdbaec8e022bb1a582a145edcc6fc0edac0e"},{"last_affected":"453cbdbaec8e022bb1a582a145edcc6fc0edac0e"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:simplemachines:simple_machines_forum:2.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.1"},{"last_affected":"2.1"}]}}],"versions":["2.1","v2.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5726.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}