PhpokCVEs & Vulnerabilities

23 CVEs affecting Phpok products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

phpok 21oklite 2
CVE-2024-44867HIGH

phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

10 Sep 2024
7.5
CVSS
CVE-2024-38953MEDIUM

phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.

1 Jul 2024
6.1
CVSS
CVE-2023-29881MEDIUM

phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.

14 May 2024
6.5
CVSS
CVE-2020-21486HIGH

SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.

20 Jun 2023
7.5
CVSS
CVE-2023-33601HIGH

An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file.

7 Jun 2023
8.8
CVSS
CVE-2023-2888HIGH

A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.

25 May 2023
8.8
CVSS
CVE-2022-47129CRITICAL

PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.

11 May 2023
9.8
CVSS
CVE-2021-34076HIGH

File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.

11 May 2023
8.8
CVSS
CVE-2022-40889CRITICAL

Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

18 Oct 2022
9.8
CVSS
CVE-2022-29363CRITICAL

Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.

12 May 2022
9.8
CVSS
CVE-2020-18440CRITICAL

Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.

2 Nov 2021
9.8
CVSS
CVE-2020-18439CRITICAL

An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell.

2 Nov 2021
9.1
CVSS
CVE-2020-18438HIGH

Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.

2 Nov 2021
7.5
CVSS
CVE-2020-19199HIGH

A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code.

10 May 2021
8.8
CVSS
CVE-2020-16629CRITICAL

PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.

8 Feb 2021
9.8
CVSS
CVE-2019-16132MEDIUM

An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary files via a title directory-traversal pathname followed by a crafted substring.

9 Sep 2019
6.5
CVSS
CVE-2019-16131HIGH

framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/cache/.

9 Sep 2019
8.8
CVSS
CVE-2018-20006MEDIUM

An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post&f=save (reachable via the index.php?id=book URI).

10 Dec 2018
6.1
CVSS
CVE-2018-19562HIGH

An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Program Upgrade > Compressed Packet Upgrade" action in which a .php file is inside a ZIP archive.

26 Nov 2018
8.8
CVSS
CVE-2018-16142MEDIUM

PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f function.

30 Aug 2018
6.1
CVSS
CVE-2018-12492HIGH

PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.

15 Jun 2018
7.5
CVSS
CVE-2018-12491CRITICAL

PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.

15 Jun 2018
9.8
CVSS
CVE-2018-8944CRITICAL

PHPOK 4.8.338 has an arbitrary file upload vulnerability.

23 Mar 2018
9.8
CVSS
← PrevPage 1 / 1Next →
Phpok CVEs & Vulnerabilities — 23 Tracked