Phpfm
Dulldusk · 3 CVEs
CVE-2026-72593
CRITICAL
dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access
Aug 10, 2026
CVE-2026-72592
CRITICAL
dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload
Aug 10, 2026
CVE-2023-53894
CRITICAL
phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability
Dec 16, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-72593 | dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access | CRITICAL | 0.79% | Aug 10, 2026 |
| CVE-2026-72592 | dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload | CRITICAL | 0.80% | Aug 10, 2026 |
| CVE-2023-53894 | phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability | CRITICAL | 0.62% | Dec 16, 2025 |
Showing 1 to 3 of 3 CVEs