Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attac…
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i…
phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.pri…
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang …