Home/Product/phpshe
Product

phpshe

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-3554
all versions
A vulnerability was found in phpshe 1.8. It has been rated as problematic. This issue affects some unknown processing of the file
4.3MEDIUM
CVE-2025-3553
all versions
A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_delete of th
6.3MEDIUM
CVE-2022-24132
all versions
phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target ser
7.5HIGH
CVE-2020-18020
all versions
SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "use
9.8CRITICAL
CVE-2020-18215
all versions
Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parame
8.8HIGH
CVE-2020-19165
all versions
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
9.8CRITICAL
CVE-2019-9762
all versions
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability doe
9.8CRITICAL
CVE-2019-9761
all versions
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without a
7.5HIGH
CVE-2019-9626
all versions
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
9.8CRITICAL
CVE-2019-6708
all versions
PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.
7.2HIGH
CVE-2019-6707
all versions
PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.
7.2HIGH
CVE-2018-18486
all versions
An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter.
9.8CRITICAL
CVE-2018-18485
all versions
An issue was discovered in PHPSHE 1.7. admin.php?mod=db&act=del allows remote attackers to delete arbitrary files via directory tr
7.5HIGH
CVE-2018-8943
all versions
There is a SQL injection in the PHPSHE 1.6 userbank parameter.
9.8CRITICAL
threatengine.sh