Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 23 Jan 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpkf cms
|
|
| CPEs | cpe:2.3:a:phpkf:cms:3.00:beta_y6:*:*:*:*:*:* | |
| Vendors & Products |
Phpkf cms
|
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpkf
Phpkf phpkf |
|
| Vendors & Products |
Phpkf
Phpkf phpkf |
Thu, 15 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter. | |
| Title | phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated) | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:05:56.353Z
Reserved: 2026-01-10T13:48:08.268Z
Link: CVE-2021-47753
Updated: 2026-01-15T16:13:53.666Z
Status : Analyzed
Published: 2026-01-15T16:16:06.003
Modified: 2026-01-23T18:31:05.153
Link: CVE-2021-47753
No data.
OpenCVE Enrichment
Updated: 2026-01-16T13:43:32Z