CVE-2024-48237
- EPSS 0.2%
- Published 25.10.2024 22:15:02
- Last modified 17.04.2025 19:00:36
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
CVE-2024-48238
- EPSS 0.13%
- Published 25.10.2024 22:15:02
- Last modified 17.04.2025 18:59:35
WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.
CVE-2024-48239
- EPSS 0.09%
- Published 25.10.2024 22:15:02
- Last modified 17.04.2025 18:56:59
An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).
CVE-2020-20343
- EPSS 0.1%
- Published 01.09.2021 22:15:07
- Last modified 21.11.2024 05:12:01
WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background.
CVE-2020-20344
- EPSS 0.26%
- Published 01.09.2021 22:15:07
- Last modified 21.11.2024 05:12:01
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.
CVE-2020-20345
- EPSS 0.3%
- Published 01.09.2021 22:15:07
- Last modified 21.11.2024 05:12:02
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
CVE-2020-20347
- EPSS 0.26%
- Published 01.09.2021 22:15:07
- Last modified 21.11.2024 05:12:02
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
CVE-2020-20348
- EPSS 0.26%
- Published 01.09.2021 22:15:07
- Last modified 21.11.2024 05:12:02
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
CVE-2020-20349
- EPSS 0.26%
- Published 01.09.2021 22:15:07
- Last modified 21.11.2024 05:12:02
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
CVE-2019-16719
- EPSS 0.16%
- Published 23.09.2019 14:15:10
- Last modified 21.11.2024 04:31:03
WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.