Vendorsphomeempirecmsany version
Vulnerabilities

phome EmpireCMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-15423
EmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted upload
Published 2026-01-02 · Analyzed
8.8EPSS 0.004
CVE-2025-15422
EmpireSoft EmpireCMS IP Address connect.php egetip protection mechanism
Published 2026-01-02 · Analyzed
7.5EPSS 0.012
CVE-2018-19462
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
Published 2019-06-07 · Modified
7.2EPSS 0.022
CVE-2018-6880
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
Published 2018-02-12 · Modified
5.3EPSS 0.018
CVE-2018-19461
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
Published 2019-06-07 · Modified
4.8EPSS 0.009