CVE-2020-18263: PHP-CMS Project PHP-CMS

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.

Affected products

Published 2021-11-03. Last modified 2026-06-17.