CVE-2026-39903 is an authorization bypass vulnerability in Simple Machines Forum 2.1 prior to 2.1.8 and 3.0 prior to 3.0 Alpha 5. The vulnerability exists in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user permissions. This allows an authenticated low-privileged user to approve, reject, or delete any pending attach [truncated]
CVE-2016-5727 is a high-severity flaw in Simple Machines Forum (SMF) 2.1. NVD describes the issue as PHP object injection in LogInOut.php, with attacker-controlled variables used in a foreach loop leading to arbitrary PHP code execution. Because the attack is network-reachable and requires no privileges, internet-facing SMF 2.1 deployments should treat this as a priority fix.
CVE-2016-5726 is a critical remote code execution issue in Simple Machines Forum 2.1. The vulnerability is described as PHP object injection in Packages.php, reachable through the themechanges array parameter, with the potential to execute arbitrary PHP code.