CVE-2018-6880: Phome Empirecms

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.

Affected products

  • Phome Empirecms: from 6.6, up to and including 7.2

Published 2018-02-12. Last modified 2026-06-17.