CVE-2021-47783
EUVD-2026-300916.01.2026, 00:16
Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| phpwcms | phpwcms | 1.9.30 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration