CVE-2025-5149
- EPSS 0.19%
- Veröffentlicht 25.05.2025 13:15:19
- Zuletzt bearbeitet 03.06.2025 12:59:06
A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the file /index.php?articleadmin/getallcon of the component Login. The manipulation of the argument uid...
CVE-2025-3800
- EPSS 0.05%
- Veröffentlicht 19.04.2025 11:31:04
- Zuletzt bearbeitet 15.07.2025 19:52:04
A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php. The manipulation of the argument mobile_phone leads to sql injection...
CVE-2025-3799
- EPSS 0.05%
- Veröffentlicht 19.04.2025 10:31:04
- Zuletzt bearbeitet 15.07.2025 20:00:28
A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousController.php. The manipulation of the argument email/username leads to sql injection. It is possible to la...
CVE-2025-3798
- EPSS 0.08%
- Veröffentlicht 19.04.2025 10:15:15
- Zuletzt bearbeitet 15.07.2025 20:01:41
A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminController.php of the component Advertisement Image Handler. The manipulation leads to unrestricted upload...
CVE-2025-2979
- EPSS 0.04%
- Veröffentlicht 31.03.2025 06:15:29
- Zuletzt bearbeitet 09.10.2025 15:35:49
A vulnerability classified as problematic has been found in WCMS 11. This affects an unknown part of the file /index.php?anonymous/setregister of the component Registration. The manipulation of the argument Username leads to cross site scripting. It ...
CVE-2025-2978
- EPSS 0.1%
- Veröffentlicht 31.03.2025 06:15:29
- Zuletzt bearbeitet 09.10.2025 15:39:56
A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=container&CKEditorFuncNum=1 of the component Article Publishing Page. The ...
CVE-2024-8875
- EPSS 0.13%
- Veröffentlicht 15.09.2024 22:15:09
- Zuletzt bearbeitet 20.09.2024 22:44:16
A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. The manipulation of the argument p leads to path traversal. The attack can be launche...
CVE-2020-19902
- EPSS 4.55%
- Veröffentlicht 27.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:28
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.
CVE-2023-31689
- EPSS 5.05%
- Veröffentlicht 22.05.2023 20:15:10
- Zuletzt bearbeitet 28.01.2025 16:15:35
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any fi...
CVE-2020-24140
- EPSS 0.25%
- Veröffentlicht 07.04.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:14:25
Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the pagename parameter to wex/html.php. It can help identify open ports, local network hosts and execute comm...