CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2021-47783 MEDIUM

Phpwcms 1.9.30 - Arbitrary File Upload

CVSS 5.3 EPSS 0.33% Jan 15, 2026
CVE-2025-5499 MEDIUM

slackero phpwcms image_resized.php getimagesize deserialization

CVSS 6.9 EPSS 0.78% Jun 3, 2025
CVE-2025-5498 MEDIUM

slackero phpwcms Custom Source Tab cnt21.readform.inc.php is_file deserialization

CVSS 5.1 EPSS 0.51% Jun 3, 2025
CVE-2025-5497 MEDIUM

slackero phpwcms Feedimport processing.inc.php deserialization

CVSS 5.3 EPSS 0.62% Jun 3, 2025
CVE-2021-36426 HIGH

File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php.

CVSS 8.8 EPSS 1.06% Feb 3, 2023
CVE-2021-36425 MEDIUM

Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlink method in include…

CVSS 5.4 EPSS 0.97% Feb 3, 2023
CVE-2021-36424 CRITICAL

An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

CVSS 9.8 EPSS 1.18% Feb 3, 2023
CVE-2021-4301 CRITICAL

slackero phpwcms sql injection

CVSS 9.8 EPSS 0.69% Jan 7, 2023
CVE-2021-4302 MEDIUM

slackero phpwcms SVG File cross site scripting

CVSS 6.1 EPSS 0.53% Jan 4, 2023
CVE-2020-19855 MEDIUM

phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.

CVSS 6.1 EPSS 0.66% Sep 7, 2021
CVE-2020-21784 CRITICAL

phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

CVSS 9.8 EPSS 1.40% Jun 24, 2021
CVE-2018-12990 MEDIUM

phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

CVSS 5.3 EPSS 1.18% Jun 30, 2018
CVE-2017-15872 MEDIUM

phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.

CVSS 4.8 EPSS 0.51% Oct 24, 2017
CVE-2011-3789 MEDIUM

phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error…

CVSS 5.0 EPSS 1.23% Sep 24, 2011
CVE-2006-7019 HIGH

phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via crafted arguments to the (1) text_evento and (2) email…

CVSS 7.5 EPSS 2.48% Feb 15, 2007
CVE-2006-6886 MEDIUM

phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.addit…

CVSS 5.0 EPSS 1.62% Jan 5, 2007
CVE-2006-2519 LOW

Directory traversal vulnerability in include/inc_ext/spaw/spaw_control.class.php in phpwcms 1.2.5-DEV allows remote attackers to include arbitrary local files…

CVSS 2.6 EPSS 1.65% May 22, 2006
CVE-2006-2518 LOW

Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows remote attackers to inject arbitrary web script or HTML via the BL[be_cnt_plainhtml] param…

CVSS 2.6 EPSS 1.39% May 22, 2006
CVE-2005-3789 MEDIUM

Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter…

CVSS 5.0 EPSS 3.42% Nov 24, 2005

Showing 1 to 19 CVEs · page 1