CVE-2018-10759: Projectpier

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.

Affected products

Published 2018-05-16. Last modified 2026-06-17.