Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2021-47783 Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attac… Phpwcms No fix yet Fix from $1,6002026-01-16 CRITICAL 9.8 CVE-2025-5499 A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the f… Phpwcms 1.9.46 / 1.10.9+ Fix from $2,3002025-06-03 HIGH 7.2 CVE-2025-5498 A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/i… Phpwcms 1.9.46 / 1.10.9+ Fix from $1,9502025-06-03 CRITICAL 9.8 CVE-2025-5497 A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_… Phpwcms 1.10.8+ Fix from $2,3002025-06-03 CRITICAL 9.8 CVE-2021-36424 An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation. Phpwcms 1.9.26+ Fix from $2,3002023-02-03 HIGH 8.8 CVE-2021-36426 File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php. Phpwcms 1.9.26+ Fix from $1,9502023-02-03 MEDIUM 5.4 CVE-2021-36425 Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlink method … Phpwcms 1.9.26+ Fix from $1,6002023-02-03 CRITICAL 9.8 CVE-2021-4301 A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical. Affected by this issue is some unknown functionality. The mani… Phpwcms 1.9.27+ Fix from $2,3002023-01-07 MEDIUM 6.1 CVE-2021-4302 A vulnerability was found in slackero phpwcms up to 1.9.26. It has been classified as problematic. This affects an unknown part of the component SVG … Phpwcms 1.9.27+ Fix from $1,6002023-01-04 MEDIUM 6.1 CVE-2020-19855 phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php. Phpwcms No fix yet Fix from $1,6002021-09-08 CRITICAL 9.8 CVE-2020-21784 phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php. Phpwcms No fix yet Fix from $2,3002021-06-24 MEDIUM 5.3 CVE-2018-12990 phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field. Phpwcms No fix yet Fix from $1,6002018-06-30 MEDIUM 5.0 CVE-2011-3789 phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i… Phpwcms Mitigation only Fix from $1,6002011-09-24 HIGH 7.5 CVE-2006-7019 phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via crafted arguments to the (1) text_evento and… Phpwcms after 1.2.5_dev Fix from $1,9502007-02-15 MEDIUM 5.0 CVE-2006-6886 phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.pri… Phpwcms No fix yet Fix from $1,6002006-12-31 MEDIUM 5.0 CVE-2005-3789 Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang … Phpwcms No fix yet Fix from $1,6002005-11-24