Vulnerabilities > Phome > Empirecms > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2022-28585 SQL Injection vulnerability in Phome Empirecms 7.5
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
network
low complexity
phome CWE-89
critical
9.8
2021-08-17 CVE-2020-22937 Code Injection vulnerability in Phome Empirecms 7.5
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
network
low complexity
phome CWE-94
critical
9.8
2018-12-20 CVE-2018-20300 Code Injection vulnerability in Phome Empirecms 7.5
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
network
low complexity
phome CWE-94
critical
9.8
2018-10-31 CVE-2018-18869 Path Traversal vulnerability in Phome Empirecms 7.5
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
network
low complexity
phome CWE-22
critical
9.8