CVE-2018-12995: Onefilecms
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen.
Affected products
- Onefilecms Onefilecms: up to and including 2012-04-14
Published 2018-06-29. Last modified 2026-06-17.