Known Vulnerabilities for products from Phome
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Phome".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-15423 json | A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file ... | Not Provided | 2026-01-02 | 2026-04-29 |
| CVE-2022-28585 json | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php | 9.8 - CRITICAL | 2022-05-03 | 2022-05-09 |
| CVE-2020-22937 json | A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writ... | 9.8 - CRITICAL | 2021-08-17 | 2022-10-26 |
| CVE-2019-12362 json | EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php. | 6.1 - MEDIUM | 2019-05-27 | 2019-05-28 |
| CVE-2019-12361 json | EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the d... | 6.1 - MEDIUM | 2019-05-27 | 2020-08-24 |
| CVE-2018-20300 json | Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm actio... | 9.8 - CRITICAL | 2018-12-20 | 2019-02-05 |
| CVE-2018-19462 json | admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses... | 7.2 - HIGH | 2019-06-07 | 2023-11-07 |
| CVE-2018-19461 json | admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php. | 4.8 - MEDIUM | 2019-06-07 | 2023-11-07 |
| CVE-2018-18869 json | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename ... | 9.8 - CRITICAL | 2018-10-31 | 2018-12-10 |
| CVE-2018-18449 json | EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue... | 8.8 - HIGH | 2019-03-07 | 2019-03-08 |
| CVE-2018-18086 json | EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by l... | 8.8 - HIGH | 2018-10-09 | 2018-11-25 |
| CVE-2018-16339 json | An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/A... | 8.8 - HIGH | 2018-09-02 | 2018-10-25 |
| CVE-2018-6881 json | EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php. | 5.3 - MEDIUM | 2018-02-12 | 2022-02-19 |
| CVE-2018-6880 json | EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/conne... | 5.3 - MEDIUM | 2018-02-12 | 2022-02-19 |
| CVE-2012-5777 json | Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 a... | Not Provided | 2012-11-16 | 2026-04-29 |
Known software with vulnerabilities from Phome
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Phome | Empirecms | 6.6 |