CVE-2017-15872: Phpwcms

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.

Affected products

  • Phpwcms Phpwcms: version 1.8.9 only

Published 2017-10-24. Last modified 2026-06-17.