ZeroHour

Vulnerabilities

32 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-47783
Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript.

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.

NVD description · AI analysis pending
5.3<1% PoC
  • phpwcms phpwcms
CVE-2025-5499
+2 in the same advisory: …5498 …5497
A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8.

A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the file image_resized.php. The manipulation of the argument imgfile leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.46 and 1.10.9 is able to address this issue. It is recommended to upgrade the affected component.

NVD description · AI analysis pending
6.9
group max
<1% PoC
  • phpwcms phpwcms
CVE-2025-5149
A vulnerability was found in WCMS up to 8.3.11.

A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the file /index.php?articleadmin/getallcon of the component Login. The manipulation of the argument uid leads to improper authentication. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.3<1% PoC
  • wcms wcms
CVE-2025-3800
+2 in the same advisory: …3799 …3798
A vulnerability has been found in WCMS 11 and classified as critical.

A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php. The manipulation of the argument mobile_phone leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

NVD description · AI analysis pending
6.9
group max
<1% PoC
  • wcms wcms
CVE-2025-2978
+1 in the same advisory: …2979
A vulnerability was found in WCMS 11.

A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=container&CKEditorFuncNum=1 of the component Article Publishing Page. The manipulation of the argument Upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3
group max
<1% PoC
  • wcms wcms
CVE-2024-8875
A vulnerability classified as critical was found in vedees wcms up to 0.3.2.

A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. The manipulation of the argument p leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3<1% PoC
  • wcms wcms
CVE-2024-37878
Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,

Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php" PHP directly echoes parameters input from external sources

NVD description · AI analysis pending
6.1<1%
  • twcms twcms
CVE-2024-31574
Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script

Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script

NVD description · AI analysis pending
5.0<1% PoC
  • twcms twcms
CVE-2020-19902
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.

Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.

NVD description · AI analysis pending
9.82% PoC
  • wcms wcms
CVE-2023-31689
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textA

In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, and write malicious code to execute scripts to trigger command execution.

NVD description · AI analysis pending
9.820% PoC
  • wcms wcms
CVE-2021-36424
+2 in the same advisory: …36426 …36425
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • phpwcms phpwcms
CVE-2021-4301
A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical.

A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument $phpwcms['db_prepend'] leads to sql injection. The attack may be launched remotely. Upgrading to version 1.9.27 is able to address this issue. The patch is identified as 77dafb6a8cc1015f0777daeb5792f43beef77a9d. It is recommended to upgrade the affected component. VDB-217418 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1%
  • phpwcms phpwcms
CVE-2021-4302
A vulnerability was found in slackero phpwcms up to 1.9.26.

A vulnerability was found in slackero phpwcms up to 1.9.26. It has been classified as problematic. This affects an unknown part of the component SVG File Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.9.27 is able to address this issue. The patch is named b39db9c7ad3800f319195ff0e26a0981395b1c54. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217419.

NVD description · AI analysis pending
6.1<1%
  • phpwcms phpwcms
CVE-2020-19855
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.

phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.

NVD description · AI analysis pending
6.1<1% PoC
  • phpwcms phpwcms
CVE-2020-21784
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

NVD description · AI analysis pending
9.81% PoC
  • phpwcms phpwcms
CVE-2020-24136
Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html

Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php.

NVD description · AI analysis pending
8.6
group max
2% PoC
  • wcms wcms
CVE-2019-14240
WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.

WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.

NVD description · AI analysis pending
8.1<1%
  • wcms wcms
CVE-2019-11377
wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according to the fm_g

wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according to the fm_get_text_exts function.

NVD description · AI analysis pending
8.82% PoC ×2
  • wcms wcms
CVE-2018-12990
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

NVD description · AI analysis pending
5.31% PoC
  • phpwcms phpwcms
CVE-2017-15872
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.

phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.

NVD description · AI analysis pending
4.8<1%
  • phpwcms phpwcms