CVE-2018-12263: Portfoliocms Project Portfoliocms

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI.

Affected products

Published 2018-06-13. Last modified 2026-06-17.