ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-3553
+1 in the same advisory: …3554
A vulnerability was found in phpshe 1.8.

A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_delete of the file /admin.php?mod=brand&act=del. The manipulation of the argument brand_id[] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • phpshe phpshe
CVE-2022-24132
phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service.

phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service.

NVD description · AI analysis pending
7.51% PoC
  • phpshe phpshe
CVE-2020-18020
SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafte

SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.

NVD description · AI analysis pending
9.84% PoC
  • phpshe mall system
CVE-2020-18215
Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote

Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code.

NVD description · AI analysis pending
8.82% PoC ×2
  • phpshe phpshe
CVE-2020-19165
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.

PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.

NVD description · AI analysis pending
9.82% PoC
  • phpshe phpshe
CVE-2019-9762
+1 in the same advisory: …9761
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id.

A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.

NVD description · AI analysis pending
9.8
group max
6% PoC
  • phpshe phpshe
CVE-2019-9626
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.

PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.

NVD description · AI analysis pending
9.81% PoC
  • phpshe phpshe
CVE-2019-6708
+1 in the same advisory: …6707
PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.

PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.

NVD description · AI analysis pending
7.2<1% PoC
  • phpshe phpshe
CVE-2018-18486
+1 in the same advisory: …18485
An issue was discovered in PHPSHE 1.7.

An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • phpshe phpshe
CVE-2018-8943
There is a SQL injection in the PHPSHE 1.6 userbank parameter.

There is a SQL injection in the PHPSHE 1.6 userbank parameter.

NVD description · AI analysis pending
9.81%
  • phpshe phpshe