Vulnerabilities
Vulnerable Software
Phome:  >> Empirecms  >> 7.5  Security Vulnerabilities
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
6.3
EPSS Score
0.0
Published
2026-01-02
A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulation causes protection mechanism failure. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
5.3
EPSS Score
0.002
Published
2026-01-02
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
CVSS Score
7.2
EPSS Score
0.009
Published
2024-01-09
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
CVSS Score
9.8
EPSS Score
0.002
Published
2022-05-03
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
CVSS Score
9.8
EPSS Score
0.034
Published
2021-08-17
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
CVSS Score
4.8
EPSS Score
0.003
Published
2019-06-07
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
CVSS Score
7.2
EPSS Score
0.003
Published
2019-06-07
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-03-07
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
CVSS Score
9.8
EPSS Score
0.01
Published
2018-12-20
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
CVSS Score
9.8
EPSS Score
0.038
Published
2018-10-31


Contact Us

Shodan ® - All rights reserved