Phpwcms records
20 published records for vendor phpwcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-21784No exploit | phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.phpwcms · phpwcms · CWE-94 | Critical9.8 | — | 1.4% | Jun 24, 2021 |
39Monitor | CVE-2021-36424No exploit | An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.phpwcms · phpwcms · CWE-94 | Critical9.8 | — | 1.2% | Feb 3, 2023 |
39Monitor | CVE-2021-4301No exploit | slackero phpwcms sql injectionphpwcms · phpwcms · CWE-89 | Critical9.8 | — | 0.7% | Jan 7, 2023 |
35Monitor | CVE-2021-36426No exploit | File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/generalphpwcms · phpwcms · CWE-434 | High8.8 | — | 1.1% | Feb 3, 2023 |
31Monitor | CVE-2006-7019No exploit | phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via crafted arguments to the (1) text_ephpwcms · phpwcms | High7.5 | — | 2.5% | Feb 14, 2007 |
27Monitor | CVE-2025-5499No exploit | slackero phpwcms image_resized.php getimagesize deserializationphpwcms · phpwcms · CWE-20 | Medium6.9 | — | 0.8% | Jun 3, 2025 |
24Monitor | CVE-2020-19855No exploit | phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.phpwcms · phpwcms · CWE-79 | Medium6.1 | — | 0.7% | Sep 7, 2021 |
24Monitor | CVE-2021-4302No exploit | slackero phpwcms SVG File cross site scriptingphpwcms · phpwcms · CWE-79 | Medium6.1 | — | 0.5% | Jan 4, 2023 |
21Monitor | CVE-2005-3789Proof of concept | Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a ..phpwcms · phpwcms | Medium5.0 | — | 3.4% | Nov 24, 2005 |
21Monitor | CVE-2018-12990No exploit | phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.phpwcms · phpwcms · CWE-200 | Medium5.3 | — | 1.2% | Jun 30, 2018 |
21Monitor | CVE-2021-36425No exploit | Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlinphpwcms · phpwcms · CWE-22 | Medium5.4 | — | 1.0% | Feb 3, 2023 |
21Monitor | CVE-2021-47783No exploit | Phpwcms 1.9.30 - Arbitrary File Uploadphpwcms · phpwcms · CWE-434 | Medium5.3 | — | 0.3% | Jan 15, 2026 |
20Monitor | CVE-2006-6886No exploit | phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) phpwcms · phpwcms · CWE-200 | Medium5.0 | — | 1.6% | Dec 31, 2006 |
20Monitor | CVE-2011-3789No exploit | phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatiphpwcms · phpwcms · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
20Monitor | CVE-2025-5498No exploit | slackero phpwcms Custom Source Tab cnt21.readform.inc.php is_file deserializationphpwcms · phpwcms · CWE-20 | Medium5.1 | — | 0.5% | Jun 3, 2025 |
19Monitor | CVE-2017-15872No exploit | phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_logiphpwcms · phpwcms · CWE-79 | Medium4.8 | — | 0.5% | Oct 24, 2017 |
18Monitor | CVE-2005-3790Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web scphpwcms · phpwcms | Medium4.3 | — | 1.8% | Nov 24, 2005 |
10Monitor | CVE-2006-2519No exploit | Directory traversal vulnerability in include/inc_ext/spaw/spaw_control.class.php in phpwcms 1.2.5-DEV allows remote attackers to include arbphpwcms · phpwcms | Low2.6 | — | 1.6% | May 22, 2006 |
10Monitor | CVE-2006-2518No exploit | Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows remote attackers to inject arbitrary web script or HTML via the BL[be_cphpwcms · phpwcms | Low2.6 | — | 1.4% | May 22, 2006 |
8Monitor | CVE-2025-5497No exploit | slackero phpwcms Feedimport processing.inc.php deserializationphpwcms · phpwcms · CWE-20 | Low2.1 | — | 0.6% | Jun 3, 2025 |
- CVE-2020-2178439Monitor
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
CriticalCVSS 9.8No exploitEPSS 1%phpwcms · phpwcmsJun 24, 2021
- CVE-2021-3642439Monitor
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.
CriticalCVSS 9.8No exploitEPSS 1%phpwcms · phpwcmsFeb 3, 2023
- CVE-2021-430139Monitor
slackero phpwcms sql injection
CriticalCVSS 9.8No exploitEPSS 1%phpwcms · phpwcmsJan 7, 2023
- CVE-2021-3642635Monitor
File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general
HighCVSS 8.8No exploitEPSS 1%phpwcms · phpwcmsFeb 3, 2023
- CVE-2006-701931Monitor
phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via crafted arguments to the (1) text_e
HighCVSS 7.5No exploitEPSS 2%phpwcms · phpwcmsFeb 14, 2007
- CVE-2025-549927Monitor
slackero phpwcms image_resized.php getimagesize deserialization
MediumCVSS 6.9No exploitEPSS 1%phpwcms · phpwcmsJun 3, 2025
- CVE-2020-1985524Monitor
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.
MediumCVSS 6.1No exploitEPSS 1%phpwcms · phpwcmsSep 7, 2021
- CVE-2021-430224Monitor
slackero phpwcms SVG File cross site scripting
MediumCVSS 6.1No exploitEPSS 1%phpwcms · phpwcmsJan 4, 2023
- CVE-2005-378921Monitor
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 3%phpwcms · phpwcmsNov 24, 2005
- CVE-2018-1299021Monitor
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
MediumCVSS 5.3No exploitEPSS 1%phpwcms · phpwcmsJun 30, 2018
- CVE-2021-3642521Monitor
Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlin
MediumCVSS 5.4No exploitEPSS 1%phpwcms · phpwcmsFeb 3, 2023
- CVE-2021-4778321Monitor
Phpwcms 1.9.30 - Arbitrary File Upload
MediumCVSS 5.3No exploitEPSS 0%phpwcms · phpwcmsJan 15, 2026
- CVE-2006-688620Monitor
phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2)
MediumCVSS 5.0No exploitEPSS 2%phpwcms · phpwcmsDec 31, 2006
- CVE-2011-378920Monitor
phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installati
MediumCVSS 5.0No exploitEPSS 1%phpwcms · phpwcmsSep 23, 2011
- CVE-2025-549820Monitor
slackero phpwcms Custom Source Tab cnt21.readform.inc.php is_file deserialization
MediumCVSS 5.1No exploitEPSS 1%phpwcms · phpwcmsJun 3, 2025
- CVE-2017-1587219Monitor
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_logi
MediumCVSS 4.8No exploitEPSS 1%phpwcms · phpwcmsOct 24, 2017
- CVE-2005-379018Monitor
Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web sc
MediumCVSS 4.3Proof of conceptEPSS 2%phpwcms · phpwcmsNov 24, 2005
- CVE-2006-251910Monitor
Directory traversal vulnerability in include/inc_ext/spaw/spaw_control.class.php in phpwcms 1.2.5-DEV allows remote attackers to include arb
LowCVSS 2.6No exploitEPSS 2%phpwcms · phpwcmsMay 22, 2006
- CVE-2006-251810Monitor
Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows remote attackers to inject arbitrary web script or HTML via the BL[be_c
LowCVSS 2.6No exploitEPSS 1%phpwcms · phpwcmsMay 22, 2006
- CVE-2025-54978Monitor
slackero phpwcms Feedimport processing.inc.php deserialization
LowCVSS 2.1No exploitEPSS 1%phpwcms · phpwcmsJun 3, 2025