Wintercms

Winter

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 09.12.2024 21:15:08
  • Zuletzt bearbeitet 24.06.2025 16:34:55

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access to the CMS templates sections that modify Twig files to bypass the sandb...

Exploit
  • EPSS 3.46%
  • Veröffentlicht 29.03.2024 16:15:08
  • Zuletzt bearbeitet 28.05.2025 19:04:33

Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes this because the payload could ...

  • EPSS 46.29%
  • Veröffentlicht 29.12.2023 00:15:50
  • Zuletzt bearbeitet 21.11.2024 08:39:08

Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via ...

  • EPSS 0.36%
  • Veröffentlicht 28.12.2023 23:15:43
  • Zuletzt bearbeitet 21.11.2024 08:39:08

Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upl...

  • EPSS 0.32%
  • Veröffentlicht 28.12.2023 23:15:43
  • Zuletzt bearbeitet 21.11.2024 08:39:08

Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be rendered unescaped in the backend form, potentially allowing for ...

Exploit
  • EPSS 0.94%
  • Veröffentlicht 07.07.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:11:21

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backend.manage_branding` permission can upload SVGs as the application logo. Prior to version 1.2.3, SVG uploads were not sanitized, whi...

  • EPSS 1.03%
  • Veröffentlicht 26.10.2022 15:15:20
  • Zuletzt bearbeitet 21.11.2024 07:18:06

Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The...