Official Product Homepageproduct
http://www.phpwcms.org/ CVE-2021-47783
MEDIUM
Phpwcms 1.9.30 - Arbitrary File Upload
Record summary
CVE-2021-47783 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.
Description
Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PhpwcmsBrowse Phpwcms / Phpwcms | CVE List | 1.9.30 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPhpwcms 1.9.30 - Arbitrary File UploadExploitDB exploitby Okan KurtulusNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47783 ExploitDB-50363exploit
https://www.exploit-db.com/exploits/50363 VulnCheck Advisory: Phpwcms 1.9.30 - Arbitrary File UploadThird-party advisory
https://www.vulncheck.com/advisories/phpwcms-arbitrary-file-upload