Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Jan 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform. | |
| Title | Phpwcms 1.9.30 - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-15T23:25:38.320Z
Reserved: 2026-01-14T14:39:44.737Z
Link: CVE-2021-47783
No data.
Status : Received
Published: 2026-01-16T00:16:21.503
Modified: 2026-01-16T00:16:21.503
Link: CVE-2021-47783
No data.
OpenCVE Enrichment
No data.