PhomeCVEs & Vulnerabilities

17 CVEs affecting Phome products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

empirecms 19
CVE-2025-15423HIGH

A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

2 Jan 2026
8.8
CVSS
CVE-2025-15422HIGH

A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulation causes protection mechanism failure. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

2 Jan 2026
7.5
CVSS
CVE-2023-50162HIGH

SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.

9 Jan 2024
7.2
CVSS
CVE-2022-28585CRITICAL

EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php

3 May 2022
9.8
CVSS
CVE-2020-22937CRITICAL

A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.

17 Aug 2021
9.8
CVSS
CVE-2018-19462HIGH

admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.

7 Jun 2019
7.2
CVSS
CVE-2018-19461MEDIUM

admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.

7 Jun 2019
4.8
CVSS
CVE-2019-12362MEDIUM

EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.

28 May 2019
6.1
CVSS
CVE-2019-12361MEDIUM

EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.

28 May 2019
6.1
CVSS
CVE-2018-18449HIGH

EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.

8 Mar 2019
8.8
CVSS
CVE-2018-20300CRITICAL

Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.

20 Dec 2018
9.8
CVSS
CVE-2018-18869CRITICAL

EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.

31 Oct 2018
9.8
CVSS
CVE-2018-18086HIGH

EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.

9 Oct 2018
8.8
CVSS
CVE-2018-16339HIGH

An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.

2 Sep 2018
8.8
CVSS
CVE-2018-6881MEDIUM

EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.

12 Feb 2018
5.3
CVSS
CVE-2018-6880MEDIUM

EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.

12 Feb 2018
5.3
CVSS
CVE-2012-5777MEDIUM

Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template.

16 Nov 2012
6.8
CVSS
← PrevPage 1 / 1Next →
Phome CVEs & Vulnerabilities — 17 Tracked