CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
Phpwcms 1.9.30 - Arbitrary File Upload
slackero phpwcms image_resized.php getimagesize deserialization
slackero phpwcms Custom Source Tab cnt21.readform.inc.php is_file deserialization
slackero phpwcms Feedimport processing.inc.php deserialization
File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php.
Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlink method in include…
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.
slackero phpwcms sql injection
slackero phpwcms SVG File cross site scripting
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.
phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error…
phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via crafted arguments to the (1) text_evento and (2) email…
phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.addit…
Directory traversal vulnerability in include/inc_ext/spaw/spaw_control.class.php in phpwcms 1.2.5-DEV allows remote attackers to include arbitrary local files…
Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows remote attackers to inject arbitrary web script or HTML via the BL[be_cnt_plainhtml] param…
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter…
Showing 1 to 19 CVEs · page 1