CVE-2020-18885: Phpmywind

High severity, CVSS 7.2. EPSS: 3.6% chance of exploitation in the next 30 days.

Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.

Affected products

Published 2021-08-20. Last modified 2026-06-17.