phpcms CVE Vulnerabilities & Metrics

Focus on phpcms vulnerabilities and metrics.

Last updated: 27 Apr 2025, 22:25 UTC

About phpcms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with phpcms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total phpcms CVEs: 10
Earliest CVE date: 10 Jan 2005, 05:00 UTC
Latest CVE date: 20 Feb 2025, 22:15 UTC

Latest CVE reference: CVE-2025-25960

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical phpcms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.46

Max CVSS: 7.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 8
7.0-8.9 7
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS phpcms CVEs

These are the five CVEs with the highest CVSS scores for phpcms, sorted by severity first and recency.

All CVEs for phpcms

CVE-2025-25960 phpcms vulnerability CVSS: 0 20 Feb 2025, 22:15 UTC

Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.

CVE-2025-25958 phpcms vulnerability CVSS: 0 20 Feb 2025, 22:15 UTC

Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.

CVE-2021-40910 phpcms vulnerability CVSS: 4.3 15 Jun 2022, 16:15 UTC

There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.

CVE-2020-22203 phpcms vulnerability CVSS: 7.5 16 Jun 2021, 18:15 UTC

SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.

CVE-2020-22201 phpcms vulnerability CVSS: 6.5 16 Jun 2021, 17:15 UTC

phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.

CVE-2020-22200 phpcms vulnerability CVSS: 5.0 16 Jun 2021, 17:15 UTC

Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.

CVE-2020-22199 phpcms vulnerability CVSS: 7.5 16 Jun 2021, 17:15 UTC

SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.

CVE-2019-10027 phpcms vulnerability CVSS: 3.5 25 Mar 2019, 00:29 UTC

PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.

CVE-2018-19127 phpcms vulnerability CVSS: 7.5 09 Nov 2018, 12:29 UTC

A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.

CVE-2018-14940 phpcms vulnerability CVSS: 5.0 05 Aug 2018, 18:29 UTC

PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an api.php?op=checkcode request.

CVE-2013-5939 phpcms vulnerability CVSS: 4.3 14 May 2014, 19:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject arbitrary web script or HTML via the (1) list or (2) introduce parameter to index.php.

CVE-2011-0645 phpcms vulnerability CVSS: 7.5 25 Jan 2011, 19:00 UTC

SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time parameter in a get action.

CVE-2011-0644 phpcms vulnerability CVSS: 7.5 25 Jan 2011, 19:00 UTC

SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the modelid parameter to flash_upload.php.

CVE-2008-0513 phpcms vulnerability CVSS: 7.8 31 Jan 2008, 20:00 UTC

Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to parser/parser.php, as demonstrated by a filename ending with %00.gif, a different vector than CVE-2005-1840.

CVE-2006-3019 phpcms vulnerability CVSS: 7.5 15 Jun 2006, 10:02 UTC

Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_phpcms.php, and (8) class.layout_phpcms.php, (9) parser/plugs/counter.php, and (10) parser/parser.php. NOTE: the class.cache_phpcms.php vector was also reported to affect 1.1.7.

CVE-2005-1840 phpcms vulnerability CVSS: 5.0 02 Jun 2005, 04:00 UTC

Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.

CVE-2004-1202 phpcms vulnerability CVSS: 6.8 10 Jan 2005, 05:00 UTC

Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.

CVE-2004-1203 phpcms vulnerability CVSS: 5.0 10 Jan 2005, 05:00 UTC

parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server's installation path.