← Back

Phome

phome

17 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Empirecms
empirecms

CVEs (17)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phome
1Empirecms
Apr 29, 2026
Jan 2, 2026
2.1 LOW· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched...Show more
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Phome
1Empirecms
Jan 7, 2026
Jan 2, 2026
5.5 MEDIUM· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulation causes protection mechanism failure....Show more
A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulation causes protection mechanism failure. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Phome
1Empirecms
Jun 3, 2025
Jan 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
1Phome
1Empirecms
Nov 21, 2024
May 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
1Phome
1Empirecms
Nov 21, 2024
Aug 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
1Phome
1Empirecms
Nov 21, 2024
Jun 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
1Phome
1Empirecms
Nov 21, 2024
Jun 7, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
1Phome
1Empirecms
Nov 21, 2024
May 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
1Phome
1Empirecms
Nov 21, 2024
May 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php regis...Show more
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.Show less
1Phome
1Empirecms
Nov 21, 2024
Mar 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
1Phome
1Empirecms
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
1Phome
1Empirecms
Nov 21, 2024
Oct 31, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
1Phome
1Empirecms
Nov 21, 2024
Oct 9, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
1Phome
1Empirecms
Nov 21, 2024
Sep 2, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
2Dedecms
Phome
2Dedecms
Empirecms
Nov 21, 2024
Feb 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
1Phome
1Empirecms
Nov 21, 2024
Feb 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
1Phome
1Empirecms
Apr 29, 2026
Nov 16, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template.