ZeroHour

Vulnerabilities

11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25960
+1 in the same advisory: …25958
Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the backgr

Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • phpcms phpcms
CVE-2021-40910
There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.

There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.

NVD description · AI analysis pending
6.1<1% PoC
  • phpcms phpcms
CVE-2020-22199
+3 in the same advisory: …22203 …22201 …22200
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.

SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • phpcms phpcms
CVE-2019-10027
PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.

PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.

NVD description · AI analysis pending
4.8<1% PoC ×2
  • phpcms phpcms
CVE-2018-19127
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, lea

A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.

NVD description · AI analysis pending
9.821%
  • phpcms phpcms
CVE-2018-14940
PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an api.php?op=checkcod

PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an api.php?op=checkcode request.

NVD description · AI analysis pending
7.51% PoC
  • phpcms phpcms
CVE-2018-14399
libs\classes\attachment.class.php in PHPCMS 9.6.0 allows remote attackers to upload and execute arbitrary PHP code via a .txt?.php#.jpg URI in the SRC attribute

libs\classes\attachment.class.php in PHPCMS 9.6.0 allows remote attackers to upload and execute arbitrary PHP code via a .txt?.php#.jpg URI in the SRC attribute of an IMG element within info[content] JSON data to the index.php?m=member&c=index&a=register URI.

NVD description · AI analysis pending
9.81%
  • phpcms project phpcms