phpshe records
14 published records for vendor phpshe.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2019-9762Proof of concept | A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id.phpshe · phpshe · CWE-89 | Critical9.8 | — | 6.0% | Mar 13, 2019 |
40Plan | CVE-2020-18020No exploit | SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" pphpshe · mall system · CWE-89 | Critical9.8 | — | 3.8% | Apr 28, 2021 |
39Monitor | CVE-2020-19165No exploit | PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.phpshe · phpshe · CWE-89 | Critical9.8 | — | 1.6% | Dec 11, 2020 |
39Monitor | CVE-2019-9626No exploit | PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.phpshe · phpshe · CWE-89 | Critical9.8 | — | 1.4% | Mar 7, 2019 |
39Monitor | CVE-2018-18486No exploit | An issue was discovered in PHPSHE 1.7.phpshe · phpshe · CWE-89 | Critical9.8 | — | 1.1% | Oct 18, 2018 |
39Monitor | CVE-2018-8943No exploit | There is a SQL injection in the PHPSHE 1.6 userbank parameter.phpshe · phpshe · CWE-89 | Critical9.8 | — | 1.0% | Mar 22, 2018 |
36Monitor | CVE-2020-18215No exploit | Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, whicphpshe · phpshe · CWE-89 | High8.8 | — | 2.0% | Feb 9, 2021 |
31Monitor | CVE-2018-18485No exploit | An issue was discovered in PHPSHE 1.7.phpshe · phpshe · CWE-22 | High7.5 | — | 1.8% | Oct 18, 2018 |
31Monitor | CVE-2019-9761No exploit | An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authenticatphpshe · phpshe · CWE-611 | High7.5 | — | 1.7% | Mar 13, 2019 |
30Monitor | CVE-2022-24132No exploit | phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service.phpshe · phpshe | High7.5 | — | 1.1% | Mar 30, 2022 |
28Monitor | CVE-2019-6708No exploit | PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.phpshe · phpshe · CWE-89 | High7.2 | — | 1.0% | Jan 23, 2019 |
28Monitor | CVE-2019-6707No exploit | PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.phpshe · phpshe · CWE-89 | High7.2 | — | 1.0% | Jan 23, 2019 |
21Monitor | CVE-2025-3553No exploit | phpshe admin.php pe_delete sql injectionphpshe · phpshe · CWE-74 | Medium5.3 | — | 0.6% | Apr 14, 2025 |
21Monitor | CVE-2025-3554No exploit | phpshe api.php cross site scriptingphpshe · phpshe · CWE-79 | Medium5.3 | — | 0.5% | Apr 14, 2025 |
- CVE-2019-976241Plan
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id.
CriticalCVSS 9.8Proof of conceptEPSS 6%phpshe · phpsheMar 13, 2019
- CVE-2020-1802040Plan
SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" p
CriticalCVSS 9.8No exploitEPSS 4%phpshe · mall systemApr 28, 2021
- CVE-2020-1916539Monitor
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
CriticalCVSS 9.8No exploitEPSS 2%phpshe · phpsheDec 11, 2020
- CVE-2019-962639Monitor
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
CriticalCVSS 9.8No exploitEPSS 1%phpshe · phpsheMar 7, 2019
- CVE-2018-1848639Monitor
An issue was discovered in PHPSHE 1.7.
CriticalCVSS 9.8No exploitEPSS 1%phpshe · phpsheOct 18, 2018
- CVE-2018-894339Monitor
There is a SQL injection in the PHPSHE 1.6 userbank parameter.
CriticalCVSS 9.8No exploitEPSS 1%phpshe · phpsheMar 22, 2018
- CVE-2020-1821536Monitor
Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, whic
HighCVSS 8.8No exploitEPSS 2%phpshe · phpsheFeb 9, 2021
- CVE-2018-1848531Monitor
An issue was discovered in PHPSHE 1.7.
HighCVSS 7.5No exploitEPSS 2%phpshe · phpsheOct 18, 2018
- CVE-2019-976131Monitor
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authenticat
HighCVSS 7.5No exploitEPSS 2%phpshe · phpsheMar 13, 2019
- CVE-2022-2413230Monitor
phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service.
HighCVSS 7.5No exploitEPSS 1%phpshe · phpsheMar 30, 2022
- CVE-2019-670828Monitor
PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.
HighCVSS 7.2No exploitEPSS 1%phpshe · phpsheJan 23, 2019
- CVE-2019-670728Monitor
PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.
HighCVSS 7.2No exploitEPSS 1%phpshe · phpsheJan 23, 2019
- CVE-2025-355321Monitor
phpshe admin.php pe_delete sql injection
MediumCVSS 5.3No exploitEPSS 1%phpshe · phpsheApr 14, 2025
- CVE-2025-355421Monitor
phpshe api.php cross site scripting
MediumCVSS 5.3No exploitEPSS 1%phpshe · phpsheApr 14, 2025