CVE-2016-10758: Phpkit

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.

Affected products

  • Phpkit Phpkit: version 1.6.6 only

Published 2019-05-24. Last modified 2026-06-17.