Known Vulnerabilities for products from Phpmywind
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Phpmywind".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-39503 json | PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() ... | 7.2 - HIGH | 2021-09-07 | 2021-09-14 |
| CVE-2020-21400 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.2 - HIGH | 2023-06-20 | 2023-06-27 |
| CVE-2020-21060 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-04-04 | 2023-04-07 |
| CVE-2020-19964 json | A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new admi... | Not Provided | 2021-10-14 | 2026-07-09 |
| CVE-2020-18886 json | Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_... | 7.2 - HIGH | 2021-08-20 | 2021-08-24 |
| CVE-2020-18885 json | Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the compo... | 7.2 - HIGH | 2021-08-20 | 2022-09-20 |
| CVE-2020-18230 json | Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the ... | 4.8 - MEDIUM | 2021-05-27 | 2021-05-28 |
| CVE-2020-18229 json | Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the ... | 4.8 - MEDIUM | 2021-05-27 | 2021-05-28 |
| CVE-2019-16704 json | admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS. | 4.8 - MEDIUM | 2019-09-23 | 2019-09-23 |
| CVE-2019-16703 json | admin/infolist_add.php in PHPMyWind 5.6 has stored XSS. | 6.1 - MEDIUM | 2019-09-23 | 2019-09-23 |
| CVE-2019-8435 json | admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header. | 4.8 - MEDIUM | 2019-02-18 | 2019-02-20 |
| CVE-2019-7661 json | An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-s... | 6.1 - MEDIUM | 2019-03-07 | 2019-03-08 |
| CVE-2019-7660 json | An issue was discovered in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scrip... | 6.1 - MEDIUM | 2019-03-07 | 2019-03-08 |
| CVE-2019-7403 json | An issue was discovered in PHPMyWind 5.5. It allows remote attackers to delete arbitrary folders via an admin/database_backup... | 4.9 - MEDIUM | 2019-02-05 | 2020-08-24 |
| CVE-2019-7402 json | An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode para... | 6.1 - MEDIUM | 2019-02-05 | 2020-08-24 |
| CVE-2018-17134 json | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction wi... | 7.2 - HIGH | 2018-09-17 | 2018-11-01 |
| CVE-2018-17133 json | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting. | 7.2 - HIGH | 2018-09-17 | 2018-11-01 |
| CVE-2018-17132 json | admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter. | 7.2 - HIGH | 2018-09-17 | 2018-11-01 |
| CVE-2018-17131 json | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field. | 7.2 - HIGH | 2018-09-17 | 2018-11-01 |
| CVE-2018-17130 json | PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header, | 5.4 - MEDIUM | 2018-09-17 | 2018-11-01 |
Known software with vulnerabilities from Phpmywind
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Phpmywind | Phpmywind | 2.1.0 |