Phpmywind is a modestly represented content-management and website-building platform that has accumulated a notable disclosure history relative to its focused product scope. The vulnerability exposure concentrates entirely within the core Phpmywind application and recurs consistently across a durable set of web-application input-handling and code-generation weakness classes: cross-site scripting, code injection, SQL injection, cross-site request forgery, and path traversal. These patterns reflect the application's direct role in processing user-supplied content and generating dynamic web pages, a surface area inherent to CMS platforms. Defenders deploying this platform should prioritize input validation hardening and apply available patches systematically; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpmywind over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21060HIGH SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page. | Apr 4, 2023 | 8.8 | 27 | NO | NO |
CVE-2020-19964MEDIUM A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication. | Oct 14, 2021 | 6.5 | 25 | NO | NO |
CVE-2020-18886HIGH Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'. | Aug 20, 2021 | 7.2 | 25 | NO | NO |
CVE-2020-18885HIGH Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'. | Aug 20, 2021 | 7.2 | 25 | NO | NO |
CVE-2017-12984MEDIUM PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php. | Aug 21, 2017 | 6.1 | 25 | NO | YES |
CVE-2018-17134HIGH admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field. | Sep 17, 2018 | 7.2 | 24 | NO | NO |
CVE-2018-17132HIGH admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter. | Sep 17, 2018 | 7.2 | 24 | NO | NO |
CVE-2018-17131HIGH admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field. | Sep 17, 2018 | 7.2 | 24 | NO | NO |
CVE-2021-39503HIGH PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/c | Sep 7, 2021 | 7.2 | 23 | NO | NO |
CVE-2018-17133HIGH admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting. | Sep 17, 2018 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpmywind.
Media articles that mention a CVE ID that affects a product developed by Phpmywind — matched by CVE ID, not by vendor name.