CVE-2018-19692: TP5CMS Project TP5CMS
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type.
Affected products
- TP5CMS Project TP5CMS: up to and including 2017-05-25
Published 2018-11-29. Last modified 2026-06-17.