VendorsDouCodouphpall versions
Vulnerabilities

DouCo DouPHP 1.5 20190516

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2019-12564
In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames.
Published 2019-06-02 · Modified
9.8EPSS 0.020
CVE-2018-20419
DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.
Published 2018-12-24 · Modified
8.8EPSS 0.005
CVE-2024-7917
DouPHP Favicon system.php unrestricted upload
Published 2024-08-18 · Analyzed
7.2EPSS 0.006
CVE-2026-2226
DouPHP ZIP File file.php unrestricted upload
Published 2026-02-09 · Analyzed
7.2EPSS 0.004
CVE-2022-24131
DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.
Published 2022-03-30 · Modified
6.1EPSS 0.009
CVE-2021-3370
DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php.
Published 2021-12-08 · Modified
6.1EPSS 0.006
CVE-2022-46438
A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the description parameter.
Published 2023-01-12 · Modified
5.4EPSS 0.004
CVE-2018-20566
An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page.
Published 2018-12-28 · Modified
5.3EPSS 0.013
CVE-2018-20567
An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which install.lock cannot be read.
Published 2018-12-28 · Modified
5.3EPSS 0.010
CVE-2018-20565
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter.
Published 2018-12-28 · Modified
4.8EPSS 0.005
CVE-2018-20564
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product_category.php?rec=update has XSS via the cat_name parameter.
Published 2018-12-28 · Modified
4.8EPSS 0.005
CVE-2018-20563
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/mobile.php?rec=system&act=update has XSS via the mobile_name parameter.
Published 2018-12-28 · Modified
4.8EPSS 0.005
CVE-2018-20562
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article_category.php?rec=update has XSS via the cat_name parameter.
Published 2018-12-28 · Modified
4.8EPSS 0.005
CVE-2018-20561
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article.php?rec=update has XSS via the title parameter.
Published 2018-12-28 · Modified
4.8EPSS 0.005
CVE-2018-20560
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/show.php?rec=update has XSS via the show_name parameter.
Published 2018-12-28 · Modified
4.8EPSS 0.005
CVE-2018-20559
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter.
Published 2018-12-28 · Modified
4.8EPSS 0.005
CVE-2018-20558
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/system.php?rec=update has XSS via the site_name parameter.
Published 2018-12-28 · Modified
4.8EPSS 0.005
CVE-2018-20557
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/page.php?rec=edit has XSS via the page_name parameter.
Published 2018-12-28 · Modified
4.8EPSS 0.005
CVE-2022-25574
A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.
Published 2022-03-25 · Modified
4.8EPSS 0.004
CVE-2024-57599
Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php
Published 2025-02-06 · Analyzed
4.8EPSS 0.003