All 3 CVE vulnerabilities found in phpfm, with AI-generated Chinese analysis, references, and POCs.
Vendor: Dulldusk
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-72593 | dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access CWE-306 | 9.8 | Critical | 2026-08-10 |
| CVE-2026-72592 | dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload CWE-434 | 9.8 | Critical | 2026-08-10 |
| CVE-2023-53894 | phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability CWE-1390 | 9.8 | Critical | 2025-12-16 |
All 3 known CVE vulnerabilities affecting phpfm with full Chinese analysis, references, and POCs where available.