Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpwcms MEDIUM 5.4
CVE-2021-47783

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attac…

No fix yet
Fix from $1,600 2026-01-16
Phpwcms CRITICAL 9.8
CVE-2025-5499

A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the f…

Fix: 1.9.46 / 1.10.9+
Fix from $2,300 2025-06-03
Phpwcms HIGH 7.2
CVE-2025-5498

A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/i…

Fix: 1.9.46 / 1.10.9+
Fix from $1,950 2025-06-03
Phpwcms CRITICAL 9.8
CVE-2025-5497

A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_…

Fix: 1.10.8+
Fix from $2,300 2025-06-03
Phpwcms CRITICAL 9.8
CVE-2021-36424

An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

Fix: 1.9.26+
Fix from $2,300 2023-02-03
Phpwcms HIGH 8.8
CVE-2021-36426

File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php.

Fix: 1.9.26+
Fix from $1,950 2023-02-03
Phpwcms MEDIUM 5.4
CVE-2021-36425

Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlink method …

Fix: 1.9.26+
Fix from $1,600 2023-02-03
Phpwcms CRITICAL 9.8
CVE-2021-4301

A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical. Affected by this issue is some unknown functionality. The mani…

Fix: 1.9.27+
Fix from $2,300 2023-01-07
Phpwcms MEDIUM 6.1
CVE-2021-4302

A vulnerability was found in slackero phpwcms up to 1.9.26. It has been classified as problematic. This affects an unknown part of the component SVG …

Fix: 1.9.27+
Fix from $1,600 2023-01-04
Phpwcms MEDIUM 6.1
CVE-2020-19855

phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.

No fix yet
Fix from $1,600 2021-09-08
Phpwcms CRITICAL 9.8
CVE-2020-21784

phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

No fix yet
Fix from $2,300 2021-06-24
Phpwcms MEDIUM 5.3
CVE-2018-12990

phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

No fix yet
Fix from $1,600 2018-06-30
Phpwcms MEDIUM 5.0
CVE-2011-3789

phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i…

Mitigation only
Fix from $1,600 2011-09-24
Phpwcms HIGH 7.5
CVE-2006-7019

phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via crafted arguments to the (1) text_evento and…

Fix: after 1.2.5_dev
Fix from $1,950 2007-02-15
Phpwcms MEDIUM 5.0
CVE-2006-6886

phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.pri…

No fix yet
Fix from $1,600 2006-12-31
Phpwcms MEDIUM 5.0
CVE-2005-3789

Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang …

No fix yet
Fix from $1,600 2005-11-24