phome 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
一般的な弱点パターンには vendor risk sql injection、vendor risk cross-site scripting、vendor risk csrf, and パス処理の欠陥 があり、vendor surface software deployment and vendor surface production workloads の利用場面で vendor impact session compromise、vendor impact data exposure, and ファイル上書き などのリスクが生じる可能性があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2025-15423 | A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | [email protected] | 2.1 | 0.04% | 2026-01-02 | 2026-04-29 |
| CVE-2025-15422 | A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulation causes protection mechanism failure. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | [email protected] | 5.5 | 0.16% | 2026-01-02 | 2026-01-07 |
| CVE-2023-50162 | SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function. | [email protected] | 7.2 | 0.86% | 2024-01-09 | 2025-06-03 |
| CVE-2022-28585 | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php | [email protected] | 9.8 | 0.23% | 2022-05-03 | 2024-11-21 |
| CVE-2020-22937 | A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file. | [email protected] | 9.8 | 3.36% | 2021-08-17 | 2024-11-21 |
| CVE-2018-19462 | admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php. | [email protected] | 7.2 | 0.24% | 2019-06-07 | 2024-11-21 |
| CVE-2018-19461 | admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php. | [email protected] | 4.8 | 0.29% | 2019-06-07 | 2024-11-21 |
| CVE-2019-12362 | EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php. | [email protected] | 6.1 | 0.24% | 2019-05-27 | 2024-11-21 |
| CVE-2019-12361 | EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page. | [email protected] | 6.1 | 0.06% | 2019-05-27 | 2024-11-21 |
| CVE-2018-18449 | EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339. | [email protected] | 8.8 | 0.18% | 2019-03-07 | 2024-11-21 |
| CVE-2018-20300 | Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file. | [email protected] | 9.8 | 0.99% | 2018-12-20 | 2024-11-21 |
| CVE-2018-18869 | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter. | [email protected] | 9.8 | 3.60% | 2018-10-31 | 2024-11-21 |
| CVE-2018-18086 | EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users. | [email protected] | 8.8 | 0.40% | 2018-10-09 | 2024-11-21 |
| CVE-2018-16339 | An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser. | [email protected] | 8.8 | 0.14% | 2018-09-02 | 2024-11-21 |
| CVE-2018-6881 | EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php. | [email protected] | 5.3 | 0.49% | 2018-02-12 | 2024-11-21 |
| CVE-2018-6880 | EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php. | [email protected] | 5.3 | 0.33% | 2018-02-12 | 2024-11-21 |
| CVE-2012-5777 | Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template. | [email protected] | 6.8 | 0.63% | 2012-11-16 | 2026-04-29 |