Description Vanilla 2.6.x before 2.6.4 allows remote code execution. Remediation References CVE-2018-18903 Related Vulnerabilities WordPress Plugin HD Webplayer Multiple SQL Injection Vulnerabilities (1.1) Drupal Core 5.x Arbitrary Code Execution (5.0) WordPress 5.2.x Prototype Pollution (5.2 - 5.2.14) Oracle HTTP Server Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2021-4184) Undertow Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') Vulnerability (CVE-2018-1067) Severity Critical Classification CVE-2018-18903 CWE-94 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities