Vulnerabilities (CVE)

Filtered by vendor Phome Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-22937 1 Phome 1 Empirecms 2022-07-10 7.5 HIGH 9.8 CRITICAL
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
CVE-2022-28585 1 Phome 1 Empirecms 2022-05-09 7.5 HIGH 9.8 CRITICAL
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
CVE-2018-20300 1 Phome 1 Empirecms 2019-02-05 7.5 HIGH 9.8 CRITICAL
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
CVE-2018-18869 1 Phome 1 Empirecms 2018-12-10 7.5 HIGH 9.8 CRITICAL
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.