CVE-2026-63179
- EPSS 0.35%
- Veröffentlicht 26.08.2026 18:06:14
- Zuletzt bearbeitet 09.09.2026 21:09:13
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) directives into L...
CVE-2026-54256
- EPSS 0.14%
- Veröffentlicht 26.08.2026 17:53:36
- Zuletzt bearbeitet 09.09.2026 21:09:13
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST parameter when resolving the attachment it operates o...
CVE-2026-32639
- EPSS 0.28%
- Veröffentlicht 26.08.2026 17:50:32
- Zuletzt bearbeitet 09.09.2026 21:09:13
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any s...
CVE-2026-32593
- EPSS 0.17%
- Veröffentlicht 26.08.2026 17:27:07
- Zuletzt bearbeitet 09.09.2026 21:09:13
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configured with a con...
CVE-2026-32258
- EPSS 0.22%
- Veröffentlicht 26.08.2026 16:49:06
- Zuletzt bearbeitet 09.09.2026 21:09:13
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by th...
CVE-2026-32257
- EPSS 0.22%
- Veröffentlicht 26.08.2026 16:45:12
- Zuletzt bearbeitet 09.09.2026 21:09:13
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled b...
CVE-2026-35445
- EPSS 0.25%
- Veröffentlicht 26.08.2026 16:40:51
- Zuletzt bearbeitet 09.09.2026 21:09:13
Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated backend user t...
CVE-2026-79773
- EPSS 0.39%
- Veröffentlicht 25.08.2026 15:16:05
- Zuletzt bearbeitet 28.08.2026 18:57:20
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require dire...
CVE-2026-79774
- EPSS 0.43%
- Veröffentlicht 25.08.2026 15:16:05
- Zuletzt bearbeitet 31.08.2026 20:38:54
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers ca...
CVE-2026-27591
- EPSS 0.49%
- Veröffentlicht 11.03.2026 21:25:35
- Zuletzt bearbeitet 19.03.2026 17:37:17
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifyi...