CVE-2019-10027: Phpcms

Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.

PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.

Affected products

  • Phpcms Phpcms: from 9.6.0, up to and including 9.6.3

Published 2019-03-25. Last modified 2026-06-17.