PhpcmsCVEs & Vulnerabilities

18 CVEs affecting Phpcms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

phpcms 22phpcms 2008 2guesbook module 1
CVE-2025-25960MEDIUM

Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.

21 Feb 2025
6.1
CVSS
CVE-2025-25958MEDIUM

Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.

21 Feb 2025
5.4
CVSS
CVE-2021-40910MEDIUM

There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.

15 Jun 2022
6.1
CVSS
CVE-2020-22203CRITICAL

SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.

16 Jun 2021
9.8
CVSS
CVE-2020-22201HIGH

phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.

16 Jun 2021
8.8
CVSS
CVE-2020-22200MEDIUM

Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.

16 Jun 2021
5.3
CVSS
CVE-2020-22199CRITICAL

SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.

16 Jun 2021
9.8
CVSS
CVE-2019-10027MEDIUM

PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.

25 Mar 2019
4.8
CVSS
CVE-2018-19127CRITICAL

A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.

9 Nov 2018
9.8
CVSS
CVE-2018-14940HIGH

PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an api.php?op=checkcode request.

5 Aug 2018
7.5
CVSS
CVE-2013-5939MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject arbitrary web script or HTML via the (1) list or (2) introduce parameter to index.php.

14 May 2014
4.3
CVSS
CVE-2011-0645HIGHpoc

SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time parameter in a get action.

25 Jan 2011
7.5
CVSS
CVE-2011-0644HIGHpoc

SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the modelid parameter to flash_upload.php.

25 Jan 2011
7.5
CVSS
CVE-2008-0513HIGHpoc

Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to parser/parser.php, as demonstrated by a filename ending with %00.gif, a different vector than CVE-2005-1840.

31 Jan 2008
7.8
CVSS
CVE-2006-3019HIGHpoc

Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_phpcms.php, and (8) class.layout_phpcms.php, (9) parser/plugs/counter.php, and (10) parser/parser.php. NOTE: the class.cache_phpcms.php vector was also reported to affect 1.1.7.

15 Jun 2006
7.5
CVSS
CVE-2005-1840MEDIUM

Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.

2 Jun 2005
5.0
CVSS
CVE-2004-1203MEDIUM

parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server's installation path.

10 Jan 2005
5.0
CVSS
CVE-2004-1202MEDIUM

Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.

10 Jan 2005
6.8
CVSS
← PrevPage 1 / 1Next →