Phome Empirecms vulnerabilities
17 known vulnerabilities affecting phome/empirecms.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH7MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2025-15423P2HIGHCVSS 8.8≤ 8.02026-01-02
CVE-2025-15423 [HIGH] CWE-284 CVE-2025-15423: A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSave
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did
nvd
CVE-2018-18869P3CRITICALCVSS 9.8v7.52018-10-31
CVE-2018-18869 [CRITICAL] CWE-22 CVE-2018-18869: EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory trav
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
nvd
CVE-2018-20300P3CRITICALCVSS 9.8v7.52018-12-20
CVE-2018-20300 [CRITICAL] CWE-94 CVE-2018-20300: Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an e
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
nvd
CVE-2020-22937P3CRITICALCVSS 9.8v7.52021-08-17
CVE-2020-22937 [CRITICAL] CWE-94 CVE-2020-22937: A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute ar
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
nvd
CVE-2025-15422P3HIGHCVSS 7.5≤ 8.02026-01-02
CVE-2025-15422 [HIGH] CWE-693 CVE-2025-15422: A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of t
A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulation causes protection mechanism failure. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this discl
nvd
CVE-2018-18086P3HIGHCVSS 8.8v7.52018-10-09
CVE-2018-18086 [HIGH] CWE-434 CVE-2018-18086: EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddo
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
nvd
CVE-2022-28585P3CRITICALCVSS 9.8v7.52022-05-03
CVE-2022-28585 [CRITICAL] CWE-89 CVE-2022-28585: EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
nvd
CVE-2018-19462P3HIGHCVSS 7.2≤ 7.5.02019-06-07
CVE-2018-19462 [HIGH] CWE-89 CVE-2018-19462: admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code vi
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
nvd
CVE-2023-50162P3HIGHCVSS 7.2v7.52024-01-09
CVE-2023-50162 [HIGH] CWE-89 CVE-2023-50162: SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
nvd
CVE-2012-5777P3MEDIUMCVSS 6.8v6.62012-11-16
CVE-2012-5777 [MEDIUM] CWE-94 CVE-2012-5777: Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/conne
Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template.
nvd
CVE-2018-18449P3HIGHCVSS 8.8v7.52019-03-07
CVE-2018-18449 [HIGH] CVE-2018-18449: EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/List
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
nvd
CVE-2018-16339P3HIGHCVSS 8.8v7.02018-09-02
CVE-2018-16339 [HIGH] CWE-352 CVE-2018-16339: An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
nvd
CVE-2018-6881P4MEDIUMCVSS 5.3v6.6v7.0+1 more2018-02-12
CVE-2018-6881 [MEDIUM] CWE-200 CVE-2018-6881: EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter t
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
nvd
CVE-2018-6880P4MEDIUMCVSS 5.3≥ 6.6, ≤ 7.22018-02-12
CVE-2018-6880 [MEDIUM] CWE-668 CVE-2018-6880: EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
nvd
CVE-2019-12362P4MEDIUMCVSS 6.1v7.5.02019-05-27
CVE-2019-12362 [MEDIUM] CWE-79 CVE-2019-12362: EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
nvd
CVE-2019-12361P4MEDIUMCVSS 6.1v7.5.02019-05-27
CVE-2019-12361 [MEDIUM] CWE-79 CVE-2019-12361: EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF p
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.
nvd
CVE-2018-19461P4MEDIUMCVSS 4.8≤ 7.5.02019-06-07
CVE-2018-19461 [MEDIUM] CWE-79 CVE-2018-19461: admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
nvd