CVE-2018-18449: Phome Empirecms

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.

Affected products

  • Phome Empirecms: version 7.5 only

Published 2019-03-07. Last modified 2026-06-17.