Vulnerabilities
Vulnerable Software
Phpcms:  >> Phpcms  Security Vulnerabilities
Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-02-20
Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-02-20
There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.
CVSS Score
6.1
EPSS Score
0.002
Published
2022-06-15
SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.
CVSS Score
9.8
EPSS Score
0.003
Published
2021-06-16
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
CVSS Score
9.8
EPSS Score
0.003
Published
2021-06-16
Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
CVSS Score
5.3
EPSS Score
0.002
Published
2021-06-16
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
CVSS Score
8.8
EPSS Score
0.004
Published
2021-06-16
PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.
CVSS Score
4.8
EPSS Score
0.002
Published
2019-03-25
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.
CVSS Score
9.8
EPSS Score
0.812
Published
2018-11-09
PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an api.php?op=checkcode request.
CVSS Score
7.5
EPSS Score
0.006
Published
2018-08-05


Contact Us

Shodan ® - All rights reserved