Phpwcms is a content management system that, despite a narrow product portfolio, occupies a notable position among small to mid-market web platforms and presents a persistent attack surface across deployed instances. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability that reflects the web-application attack classes that recur in the platform. The exposure concentrates in the core phpwcms product and recurs through weakness classes including untrusted deserialization, input-validation flaws, cross-site scripting, and information disclosure that are characteristic of content-management systems handling user-supplied content and administrative privileges. Defenders deploying or maintaining phpwcms instances should prioritize patch cycles for the platform itself, particularly for serialization-oriented and injection-class vulnerabilities that may affect data integrity or enable privilege escalation. Current exploitation status and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpwcms over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36424CRITICAL An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation. | Feb 3, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-4301CRITICAL A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument $phpwc | Jan 7, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-5497CRITICAL A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_feedimport/inc/processing.inc.p | Jun 3, 2025 | 9.8 | 28 | NO | NO |
CVE-2020-21784CRITICAL phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php. | Jun 24, 2021 | 9.8 | 28 | NO | NO |
CVE-2021-36426HIGH File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php. | Feb 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-5499CRITICAL A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the file image_resized.php. The mani | Jun 3, 2025 | 9.8 | 26 | NO | NO |
CVE-2005-3789MEDIUM Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter in login.php and (2) | Nov 24, 2005 | 5.0 | 23 | NO | YES |
CVE-2021-4302MEDIUM A vulnerability was found in slackero phpwcms up to 1.9.26. It has been classified as problematic. This affects an unknown part of the component SVG File Handler. The manipulation | Jan 4, 2023 | 6.1 | 22 | NO | NO |
CVE-2020-19855MEDIUM phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php. | Sep 8, 2021 | 6.1 | 21 | NO | NO |
CVE-2005-3790MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) i and (2) text | Nov 24, 2005 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpwcms.
Media articles that mention a CVE ID that affects a product developed by Phpwcms — matched by CVE ID, not by vendor name.