Vulnerabilities
14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-3553 +1 in the same advisory: …3554 | A vulnerability was found in phpshe 1.8. A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_delete of the file /admin.php?mod=brand&act=del. The manipulation of the argument brand_id[] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2022-24132 | phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service. phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2020-18020 | SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafte SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component. NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2020-18215 | Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code. NVD description · AI analysis pending | 8.8 | 2% | PoC ×2 |
| — | |
| CVE-2020-19165 | PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter. PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-9762 +1 in the same advisory: …9761 | A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication. NVD description · AI analysis pending | 9.8 group max | 6% | PoC |
| — | |
| CVE-2019-9626 | PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php. PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2019-6708 +1 in the same advisory: …6707 | PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter. PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2018-18486 +1 in the same advisory: …18485 | An issue was discovered in PHPSHE 1.7. An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2018-8943 | There is a SQL injection in the PHPSHE 1.6 userbank parameter. There is a SQL injection in the PHPSHE 1.6 userbank parameter. NVD description · AI analysis pending | 9.8 | 1% |
| — |