CVE-2018-12993: Onefilecms

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.

Affected products

  • Onefilecms Onefilecms: up to and including 2012-04-14

Published 2018-06-29. Last modified 2026-06-17.