CVE-2025-13786
- EPSS 0.06%
- Veröffentlicht 30.11.2025 09:15:45
- Zuletzt bearbeitet 11.12.2025 23:10:03
A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content results in code injection. It is possible to initiate ...
CVE-2025-13783
- EPSS 0.04%
- Veröffentlicht 30.11.2025 06:15:45
- Zuletzt bearbeitet 11.12.2025 23:14:38
A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/Controller/CommentadminController.class.php of the component Commentadm...
CVE-2025-13782
- EPSS 0.04%
- Veröffentlicht 30.11.2025 03:02:08
- Zuletzt bearbeitet 11.12.2025 23:17:50
A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controller/SlideController.class.php of the component SlideController. The mani...
CVE-2024-48239
- EPSS 0.08%
- Veröffentlicht 25.10.2024 22:15:02
- Zuletzt bearbeitet 17.04.2025 18:56:59
An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).
CVE-2024-48238
- EPSS 0.05%
- Veröffentlicht 25.10.2024 22:15:02
- Zuletzt bearbeitet 17.04.2025 18:59:35
WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.
CVE-2024-48237
- EPSS 0.11%
- Veröffentlicht 25.10.2024 22:15:02
- Zuletzt bearbeitet 17.04.2025 19:00:36
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
CVE-2020-20347
- EPSS 0.26%
- Veröffentlicht 01.09.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:02
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
CVE-2020-20349
- EPSS 0.26%
- Veröffentlicht 01.09.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:02
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
CVE-2020-20348
- EPSS 0.26%
- Veröffentlicht 01.09.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:02
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
CVE-2020-20345
- EPSS 0.3%
- Veröffentlicht 01.09.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:02
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.