CVE-2018-14940: Phpcms

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an api.php?op=checkcode request.

Affected products

  • Phpcms Phpcms: version 9.0 only

Published 2018-08-05. Last modified 2026-06-17.