CVE-2020-11011: Phproject

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched in version 1.7.8.

Affected products

  • Phproject Phproject: before 1.7.8 (fixed in 1.7.8)

Published 2020-04-22. Last modified 2026-06-17.