Phpok is a modestly represented web-based content-management and file-handling platform with a narrow product line centered on the core Phpok and OKLite applications. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across a consistent set of input-handling and deserialization weaknesses: unrestricted file uploads, path traversal, cross-site scripting, SQL injection, and unsafe deserialization of untrusted data. These weakness classes reflect the file-upload and dynamic content generation mechanics inherent to web-facing CMS platforms and present a direct attack surface to unauthenticated users. Defenders deploying Phpok or OKLite should prioritize input validation hardening, restrict file-upload functionality to safe types and directories, and monitor for unsafe deserialization patterns in configuration or plugin handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpok over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40889CRITICAL Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php. | Oct 18, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-12491CRITICAL PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip | Jun 15, 2018 | 9.8 | 31 | NO | NO |
CVE-2022-47129CRITICAL PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability. | May 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2019-16131HIGH framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/cache/. | Sep 9, 2019 | 8.8 | 30 | NO | NO |
CVE-2018-8944CRITICAL PHPOK 4.8.338 has an arbitrary file upload vulnerability. | Mar 22, 2018 | 9.8 | 30 | NO | NO |
CVE-2020-16629CRITICAL PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PH | Feb 8, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-34076HIGH File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload. | May 11, 2023 | 8.8 | 28 | NO | NO |
CVE-2020-18440CRITICAL Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code. | Nov 2, 2021 | 9.8 | 28 | NO | NO |
CVE-2018-19562HIGH An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Program Upgrade > Compressed Packet | Nov 26, 2018 | 8.8 | 28 | NO | NO |
CVE-2020-19199HIGH A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code. | May 10, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpok.
Media articles that mention a CVE ID that affects a product developed by Phpok — matched by CVE ID, not by vendor name.