CVE-2017-15872: Phpwcms
Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.
Affected products
- Phpwcms Phpwcms: version 1.8.9 only
Published 2017-10-24. Last modified 2026-06-17.