CVE-2021-47783

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpwcms:phpwcms:1.9.30:*:*:*:*:*:*:*

History

09 Feb 2026, 14:52

Type Values Removed Values Added
CPE cpe:2.3:a:phpwcms:phpwcms:1.9.30:*:*:*:*:*:*:*
First Time Phpwcms
Phpwcms phpwcms
References () http://www.phpwcms.org/ - () http://www.phpwcms.org/ - Product
References () https://www.exploit-db.com/exploits/50363 - () https://www.exploit-db.com/exploits/50363 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/phpwcms-arbitrary-file-upload - () https://www.vulncheck.com/advisories/phpwcms-arbitrary-file-upload - Third Party Advisory

16 Jan 2026, 22:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50363 - () https://www.exploit-db.com/exploits/50363 -

16 Jan 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 00:16

Updated : 2026-02-09 14:52


NVD link : CVE-2021-47783

Mitre link : CVE-2021-47783

CVE.ORG link : CVE-2021-47783


JSON object : View

Products Affected

phpwcms

  • phpwcms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type