Skip to content
Noroxi

Phpwcms records

20 published records for vendor phpwcms.

All records

20 records
  • phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpwcms · phpwcmsJun 24, 2021

  • An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpwcms · phpwcmsFeb 3, 2023

  • CVE-2021-4301
    39Monitor

    slackero phpwcms sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    phpwcms · phpwcmsJan 7, 2023

  • File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general

    HighCVSS 8.8No exploitEPSS 1%

    phpwcms · phpwcmsFeb 3, 2023

  • CVE-2006-7019
    31Monitor

    phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via crafted arguments to the (1) text_e

    HighCVSS 7.5No exploitEPSS 2%

    phpwcms · phpwcmsFeb 14, 2007

  • CVE-2025-5499
    27Monitor

    slackero phpwcms image_resized.php getimagesize deserialization

    MediumCVSS 6.9No exploitEPSS 1%

    phpwcms · phpwcmsJun 3, 2025

  • phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.

    MediumCVSS 6.1No exploitEPSS 1%

    phpwcms · phpwcmsSep 7, 2021

  • CVE-2021-4302
    24Monitor

    slackero phpwcms SVG File cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    phpwcms · phpwcmsJan 4, 2023

  • CVE-2005-3789
    21Monitor

    Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a ..

    MediumCVSS 5.0Proof of conceptEPSS 3%

    phpwcms · phpwcmsNov 24, 2005

  • phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

    MediumCVSS 5.3No exploitEPSS 1%

    phpwcms · phpwcmsJun 30, 2018

  • Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlin

    MediumCVSS 5.4No exploitEPSS 1%

    phpwcms · phpwcmsFeb 3, 2023

  • Phpwcms 1.9.30 - Arbitrary File Upload

    MediumCVSS 5.3No exploitEPSS 0%

    phpwcms · phpwcmsJan 15, 2026

  • CVE-2006-6886
    20Monitor

    phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2)

    MediumCVSS 5.0No exploitEPSS 2%

    phpwcms · phpwcmsDec 31, 2006

  • CVE-2011-3789
    20Monitor

    phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installati

    MediumCVSS 5.0No exploitEPSS 1%

    phpwcms · phpwcmsSep 23, 2011

  • CVE-2025-5498
    20Monitor

    slackero phpwcms Custom Source Tab cnt21.readform.inc.php is_file deserialization

    MediumCVSS 5.1No exploitEPSS 1%

    phpwcms · phpwcmsJun 3, 2025

  • phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_logi

    MediumCVSS 4.8No exploitEPSS 1%

    phpwcms · phpwcmsOct 24, 2017

  • CVE-2005-3790
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web sc

    MediumCVSS 4.3Proof of conceptEPSS 2%

    phpwcms · phpwcmsNov 24, 2005

  • CVE-2006-2519
    10Monitor

    Directory traversal vulnerability in include/inc_ext/spaw/spaw_control.class.php in phpwcms 1.2.5-DEV allows remote attackers to include arb

    LowCVSS 2.6No exploitEPSS 2%

    phpwcms · phpwcmsMay 22, 2006

  • CVE-2006-2518
    10Monitor

    Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows remote attackers to inject arbitrary web script or HTML via the BL[be_c

    LowCVSS 2.6No exploitEPSS 1%

    phpwcms · phpwcmsMay 22, 2006

  • slackero phpwcms Feedimport processing.inc.php deserialization

    LowCVSS 2.1No exploitEPSS 1%

    phpwcms · phpwcmsJun 3, 2025