CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
CVE-2025-52994 MEDIUM
gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.
CVSS 4.9 EPSS 0.69% Jul 11, 2025
CVE-2016-10508 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTML via parameters in…
CVSS 6.1 EPSS 0.83% Aug 31, 2017
CVE-2013-6919 MEDIUM
The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Reques…
CVSS 4.3 EPSS 1.19% Dec 27, 2014
CVE-2005-1898 MEDIUM
The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.
CVSS 5.0 EPSS 1.37% Jun 8, 2005
Showing 1 to 4 CVEs · page 1