Phpthumb / Phpthumb
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-52994 | gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709. | MEDIUM | 4.9 | Jul 11, 2025 |
| CVE-2016-10508 | Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTML via parameters in… | MEDIUM | 6.1 | Aug 31, 2017 |
| CVE-2013-6919 | The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Reques… | MEDIUM | 4.3 | Dec 27, 2014 |
| CVE-2005-1898 | The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images. | MEDIUM | 5.0 | Jun 8, 2005 |
Showing 1 to 3 of 3 CVEs