AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-1921

HIGH · CVSS 7.5 EPSS 79.07%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-07-05 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2005-1921
Severity
HIGH
CVSS
7.5
EPSS
79.07%
WordPress

Original NVD Description

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.