ZeroHour

Vulnerabilities

13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-47783
Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript.

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.

NVD description · AI analysis pending
5.3<1% PoC
  • phpwcms phpwcms
CVE-2025-5499
+2 in the same advisory: …5498 …5497
A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8.

A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the file image_resized.php. The manipulation of the argument imgfile leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.46 and 1.10.9 is able to address this issue. It is recommended to upgrade the affected component.

NVD description · AI analysis pending
6.9
group max
<1% PoC
  • phpwcms phpwcms
CVE-2021-36424
+2 in the same advisory: …36426 …36425
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • phpwcms phpwcms
CVE-2021-4301
A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical.

A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument $phpwcms['db_prepend'] leads to sql injection. The attack may be launched remotely. Upgrading to version 1.9.27 is able to address this issue. The patch is identified as 77dafb6a8cc1015f0777daeb5792f43beef77a9d. It is recommended to upgrade the affected component. VDB-217418 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1%
  • phpwcms phpwcms
CVE-2021-4302
A vulnerability was found in slackero phpwcms up to 1.9.26.

A vulnerability was found in slackero phpwcms up to 1.9.26. It has been classified as problematic. This affects an unknown part of the component SVG File Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.9.27 is able to address this issue. The patch is named b39db9c7ad3800f319195ff0e26a0981395b1c54. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217419.

NVD description · AI analysis pending
6.1<1%
  • phpwcms phpwcms
CVE-2020-19855
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.

phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.

NVD description · AI analysis pending
6.1<1% PoC
  • phpwcms phpwcms
CVE-2020-21784
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

NVD description · AI analysis pending
9.81% PoC
  • phpwcms phpwcms
CVE-2018-12990
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

NVD description · AI analysis pending
5.31% PoC
  • phpwcms phpwcms
CVE-2017-15872
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.

phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.

NVD description · AI analysis pending
4.8<1%
  • phpwcms phpwcms