VYPR
Unrated severityOSV Advisory· Published Jan 15, 2026· Updated Apr 7, 2026

Phpwcms 1.9.30 - Arbitrary File Upload

CVE-2021-47783

Description

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.

Affected products

1
  • Range: phpwcms-1.6.529, phpwcms-1.6.531, phpwcms-1.7.0, …

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.