paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6217.json"