CVE-2018-12995: Onefilecms

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen.

Affected products

  • Onefilecms Onefilecms: up to and including 2012-04-14

Published 2018-06-29. Last modified 2026-06-17.