CVE-2026-38669
- EPSS 0.15%
- Veröffentlicht 04.05.2026 00:00:00
- Zuletzt bearbeitet 05.05.2026 20:24:04
wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.
CVE-2025-5149
- EPSS 0.52%
- Veröffentlicht 25.05.2025 13:15:19
- Zuletzt bearbeitet 03.06.2025 12:59:06
A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the file /index.php?articleadmin/getallcon of the component Login. The manipulation of the argument uid...
CVE-2025-3800
- EPSS 0.53%
- Veröffentlicht 19.04.2025 11:31:04
- Zuletzt bearbeitet 15.07.2025 19:52:04
A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php. The manipulation of the argument mobile_phone leads to sql injection...
CVE-2025-3799
- EPSS 0.43%
- Veröffentlicht 19.04.2025 10:31:04
- Zuletzt bearbeitet 15.07.2025 20:00:28
A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousController.php. The manipulation of the argument email/username leads to sql injection. It is possible to la...
CVE-2025-3798
- EPSS 0.38%
- Veröffentlicht 19.04.2025 10:15:15
- Zuletzt bearbeitet 15.07.2025 20:01:41
A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminController.php of the component Advertisement Image Handler. The manipulation leads to unrestricted upload...
CVE-2025-2979
- EPSS 0.31%
- Veröffentlicht 31.03.2025 06:15:29
- Zuletzt bearbeitet 09.10.2025 15:35:49
A vulnerability classified as problematic has been found in WCMS 11. This affects an unknown part of the file /index.php?anonymous/setregister of the component Registration. The manipulation of the argument Username leads to cross site scripting. It ...
CVE-2025-2978
- EPSS 0.46%
- Veröffentlicht 31.03.2025 06:15:29
- Zuletzt bearbeitet 09.10.2025 15:39:56
A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=container&CKEditorFuncNum=1 of the component Article Publishing Page. The ...
CVE-2024-8875
- EPSS 0.85%
- Veröffentlicht 15.09.2024 22:15:09
- Zuletzt bearbeitet 20.09.2024 22:44:16
A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. The manipulation of the argument p leads to path traversal. The attack can be launche...
CVE-2020-19902
- EPSS 1.61%
- Veröffentlicht 27.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:28
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.
CVE-2023-31689
- EPSS 21.76%
- Veröffentlicht 22.05.2023 20:15:10
- Zuletzt bearbeitet 28.01.2025 16:15:35
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any fi...