phpcms kayıtları
phpcms üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2018-19127Kavram kanıtı | A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controphpcms · phpcms · CWE-94 | Kritik9,8 | — | %20,8 | 9 Kas 2018 |
39İzleyin | CVE-2020-22199İstismar yok | SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.phpcms · phpcms · CWE-89 | Kritik9,8 | — | %1,2 | 16 Haz 2021 |
39İzleyin | CVE-2020-22203İstismar yok | SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.phpcms · phpcms · CWE-89 | Kritik9,8 | — | %1,1 | 16 Haz 2021 |
35İzleyin | CVE-2020-22201İstismar yok | phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.phpcms · phpcms · CWE-94 | Yüksek8,8 | — | %1,5 | 16 Haz 2021 |
32İzleyin | CVE-2006-3019Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the phpcms · phpcms · CWE-94 | Yüksek7,5 | — | %7,9 | 15 Haz 2006 |
32İzleyin | CVE-2008-0513Kavram kanıtı | Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files vphpcms · phpcms · CWE-22 | Yüksek7,8 | — | %3,5 | 31 Oca 2008 |
30İzleyin | CVE-2018-14940İstismar yok | PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in anphpcms · phpcms · CWE-400 | Yüksek7,5 | — | %1,3 | 5 Ağu 2018 |
30İzleyin | CVE-2011-0644Kavram kanıtı | SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commanphpcms · phpcms 2008 · CWE-89 | Yüksek7,5 | — | %1,2 | 25 Oca 2011 |
30İzleyin | CVE-2011-0645Kavram kanıtı | SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time paramphpcms · phpcms 2008 · CWE-89 | Yüksek7,5 | — | %1,0 | 25 Oca 2011 |
28İzleyin | CVE-2004-1202İstismar yok | Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote phpcms · phpcms | Orta6,8 | — | %2,3 | 10 Oca 2005 |
24İzleyin | CVE-2021-40910İstismar yok | There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.phpcms · phpcms · CWE-79 | Orta6,1 | — | %0,7 | 15 Haz 2022 |
24İzleyin | CVE-2025-25960İstismar yok | Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member phpcms · phpcms · CWE-79 | Orta6,1 | — | %0,3 | 20 Şub 2025 |
21İzleyin | CVE-2005-1840İstismar yok | Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbiphpcms · phpcms | Orta5,0 | — | %1,8 | 2 Haz 2005 |
21İzleyin | CVE-2020-22200İstismar yok | Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.phpcms · phpcms · CWE-22 | Orta5,3 | — | %1,4 | 16 Haz 2021 |
21İzleyin | CVE-2025-25958İstismar yok | Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.phpcms · phpcms · CWE-79 | Orta5,4 | — | %0,3 | 20 Şub 2025 |
20İzleyin | CVE-2004-1203İstismar yok | parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via phpcms · phpcms | Orta5,0 | — | %1,4 | 10 Oca 2005 |
19İzleyin | CVE-2019-10027İstismar yok | PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.phpcms · phpcms · CWE-79 | Orta4,8 | — | %0,7 | 24 Mar 2019 |
18İzleyin | CVE-2013-5939İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject arbitrary web scriptphpcms · guesbook module · CWE-79 | Orta4,3 | — | %1,9 | 14 May 2014 |
- CVE-2018-1912745Planlayın
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a contro
KritikCVSS 9,8Kavram kanıtıEPSS %21phpcms · phpcms9 Kas 2018
- CVE-2020-2219939İzleyin
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
KritikCVSS 9,8İstismar yokEPSS %1phpcms · phpcms16 Haz 2021
- CVE-2020-2220339İzleyin
SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.
KritikCVSS 9,8İstismar yokEPSS %1phpcms · phpcms16 Haz 2021
- CVE-2020-2220135İzleyin
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
YüksekCVSS 8,8İstismar yokEPSS %1phpcms · phpcms16 Haz 2021
- CVE-2006-301932İzleyin
Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the
YüksekCVSS 7,5Kavram kanıtıEPSS %8phpcms · phpcms15 Haz 2006
- CVE-2008-051332İzleyin
Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files v
YüksekCVSS 7,8Kavram kanıtıEPSS %4phpcms · phpcms31 Oca 2008
- CVE-2018-1494030İzleyin
PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an
YüksekCVSS 7,5İstismar yokEPSS %1phpcms · phpcms5 Ağu 2018
- CVE-2011-064430İzleyin
SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL comman
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpcms · phpcms 200825 Oca 2011
- CVE-2011-064530İzleyin
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time param
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpcms · phpcms 200825 Oca 2011
- CVE-2004-120228İzleyin
Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote
OrtaCVSS 6,8İstismar yokEPSS %2phpcms · phpcms10 Oca 2005
- CVE-2021-4091024İzleyin
There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.
OrtaCVSS 6,1İstismar yokEPSS %1phpcms · phpcms15 Haz 2022
- CVE-2025-2596024İzleyin
Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member
OrtaCVSS 6,1İstismar yokEPSS %0phpcms · phpcms20 Şub 2025
- CVE-2005-184021İzleyin
Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbi
OrtaCVSS 5,0İstismar yokEPSS %2phpcms · phpcms2 Haz 2005
- CVE-2020-2220021İzleyin
Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
OrtaCVSS 5,3İstismar yokEPSS %1phpcms · phpcms16 Haz 2021
- CVE-2025-2595821İzleyin
Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.
OrtaCVSS 5,4İstismar yokEPSS %0phpcms · phpcms20 Şub 2025
- CVE-2004-120320İzleyin
parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via
OrtaCVSS 5,0İstismar yokEPSS %1phpcms · phpcms10 Oca 2005
- CVE-2019-1002719İzleyin
PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.
OrtaCVSS 4,8İstismar yokEPSS %1phpcms · phpcms24 Mar 2019
- CVE-2013-593918İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %2phpcms · guesbook module14 May 2014