Known Vulnerabilities for Empirecms by Phome
Listed below are 10 of the newest known vulnerabilities associated with "Empirecms" by "Phome".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-15423 json | Not Provided | 2026-01-02 | 2026-04-29 | |
| CVE-2022-28585 json | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php | 9.8 - CRITICAL | 2022-05-03 | 2022-05-09 |
| CVE-2020-22937 json | A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writ... | 9.8 - CRITICAL | 2021-08-17 | 2022-10-26 |
| CVE-2019-12362 json | EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php. | 6.1 - MEDIUM | 2019-05-27 | 2019-05-28 |
| CVE-2019-12361 json | EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the d... | 6.1 - MEDIUM | 2019-05-27 | 2020-08-24 |
| CVE-2018-20300 json | Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm actio... | 9.8 - CRITICAL | 2018-12-20 | 2019-02-05 |
| CVE-2018-19462 json | admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses... | 7.2 - HIGH | 2019-06-07 | 2023-11-07 |
| CVE-2018-19461 json | admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php. | 4.8 - MEDIUM | 2019-06-07 | 2023-11-07 |
| CVE-2018-18869 json | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename ... | 9.8 - CRITICAL | 2018-10-31 | 2018-12-10 |
| CVE-2018-18449 json | EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue... | 8.8 - HIGH | 2019-03-07 | 2019-03-08 |