CVE-2019-11574
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
Date published : 2020-03-20
https://pastebin.com/raw/prE3iiLm
https://www.simplemachines.org/community/index.php?board=1.0