VDB

GCVE-110-COMPOSER-2026-040406

GCVE-110-COMPOSER-2026-040406
Advisory Published
Vulnetix · Advisory published July 5, 2026
[PHP-SHELL-EXEC-VAR] PHP OS command execution sink invoked on a variable — matched: $response = (object) json_decode(curl_exec($ch));

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
packagistvanilla-thunder/oxid-module-withdrawal-form* (affected)

References

advisory
web

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›