github slackero/phpwcms v1.12.4
phpwcms v1.12.4

latest release: v1.9.50
3 hours ago

This release contains the security audit fixes, plus dependency updates including two CommonMark CVEs. All seven confirmed vulnerabilities and the multi-form CSRF regression are resolved.

🔒 Security Fixes

  • PHP Code Injection in the Index Page Config Writer (Critical, CWE-94): act_structure.php wrote acat_permit, acat_cntpart and acat_timeout unescaped into include/config/conf.indexpage.inc.php, a file required on every frontend request. A crafted value produced persistent remote code execution triggered by any anonymous visitor. All three values are now escaped with sanitize_quote_backslash().
  • Path Traversal / Local File Inclusion in Content Template Fields (High, CWE-22/CWE-73/CWE-98): Template and file name fields of content parts accepted ../ sequences and absolute paths, and include_ext_php() skipped its realpath() containment check whenever the caller passed a truthy flag — which cnt21.article.inc.php did. Local containment is now unconditional; the new helpers sanitize_template_name() (Unicode-safe, so existing umlaut template names keep working) and path_is_within() are applied to all template/file name fields and the cnt51 GET sinks.
  • Stored XSS in the Backend Guestbook via Spoofable Client-IP Header (High, CWE-79/CWE-113): getRemoteIP() trusted HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR without validation, so an unauthenticated guestbook post could store markup that executed in the moderation view. IP values are now validated with filter_var(FILTER_VALIDATE_IP) — a public REMOTE_ADDR is authoritative, forwarded headers count only behind a private or reserved peer — and the output is escaped and URL-encoded.
  • SQL Injection in the Structure Category INSERT (Medium, CWE-89): acat_permit and acat_cache were interpolated into phpwcms_articlecat without escaping while neighbouring values used _dbEscape(). Both are escaped now, and the group/content-part ID arrays are validated as integers.
  • Multi-Form CSRF Token Regression (High, regression from 1.12.0): Every form on a backend page shared the session key csrf_form_token and each form regenerated it, so only the last form of a page could be submitted — creating or editing backend users was impossible. The token is now generated once and reused for all forms. Refs #381.
  • Session Fixation (Medium, CWE-384): login.php did not regenerate the session ID on successful authentication and session.use_strict_mode stayed at PHP's default. The session ID is now regenerated at the auth boundary and strict mode is enabled.
  • Unauthenticated Password Reminder for Inactive Accounts (Medium, CWE-620): The public password reminder form matched accounts without checking their active state. Both lookups now require an active account.
  • Object Injection Candidates (Low, CWE-502): Three unserialize() calls omitted ['allowed_classes' => false] — fixed in cnt14, cnt50 and the shop frontend search.

📦 Dependency Updates

  • league/commonmark 2.8.3 → 2.10.3: Fixes CVE-2026-71488 (quadratic-time DoS when parsing crafted Markdown) and CVE-2026-71478 (AttributesExtension unsafe-link filter bypass).
  • enshrined/svg-sanitize 0.22.0 → 1.0.0: SVG upload sanitizer major upgrade, API used by class.svg-reader.php unchanged.
  • js-cookie 2.2.1 → 3.0.8, phpstan 2.2.16, phpspreadsheet 5.10.0, tinymce 8.9.2, htmlpurifier 4.19.1, idna-convert 4.2.2, symfony polyfills v1.43.0 and further updates within existing constraints. composer audit reports no advisories.

⚙️ Changelog Comparison

For a line-by-line code view of all changes:
Comparing v1.12.3...v1.12.4

Don't miss a new phpwcms release

NewReleases is sending notifications on new releases.