Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Wbce Cms HIGH 8.8
CVE-2022-50936

WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the a…

No fix yet
Fix from $1,950 2026-01-13
Wbce Cms MEDIUM 5.4
CVE-2023-53909

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by uploading c…

No fix yet
Fix from $1,600 2025-12-17
Wbce Cms MEDIUM 5.4
CVE-2023-53910

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting s…

No fix yet
Fix from $1,600 2025-12-17
Wbce Cms MEDIUM 6.1
CVE-2023-53901

WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attac…

No fix yet
Fix from $1,600 2025-12-16
Wbce Cms HIGH 8.8
CVE-2024-58283

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the E…

No fix yet
Fix from $1,950 2025-12-10
Wbce Cms CRITICAL 9.8
CVE-2023-39796EPSS 6%

SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RE…

Mitigation only
Fix from $2,300 2023-11-10
Wbce Cms MEDIUM 5.4
CVE-2023-43871

A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2023-09-28
Wbce Cms HIGH 7.2
CVE-2023-38947

An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a cr…

No fix yet
Fix from $1,950 2023-08-03
Wbce Cms HIGH 7.2
CVE-2023-29855

WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php.

No fix yet
Fix from $1,950 2023-04-18
Wbce Cms CRITICAL 9.8
CVE-2022-46020EPSS 39%

WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.

No fix yet
Fix from $2,300 2022-12-20
Wbce Cms HIGH 7.2
CVE-2022-45039

An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP …

No fix yet
Fix from $1,950 2022-11-25
Wbce Cms MEDIUM 5.4
CVE-2022-45040

A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or …

No fix yet
Fix from $1,600 2022-11-25
Wbce Cms MEDIUM 5.4
CVE-2022-45036

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML…

No fix yet
Fix from $1,600 2022-11-25
Wbce Cms MEDIUM 5.4
CVE-2022-45037

A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via…

No fix yet
Fix from $1,600 2022-11-25
Wbce Cms MEDIUM 5.4
CVE-2022-45038

A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML v…

No fix yet
Fix from $1,600 2022-11-25
Wbce Cms MEDIUM 5.4
CVE-2022-30072

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.

No fix yet
Fix from $1,600 2022-05-17
Wbce Cms MEDIUM 5.4
CVE-2022-30073

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.

No fix yet
Fix from $1,600 2022-05-17
Wbce Cms MEDIUM 6.1
CVE-2022-28477

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2022-04-28
Wbce Cms HIGH 7.8
CVE-2022-25099

A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $1,950 2022-02-24
Wbce Cms HIGH 7.8
CVE-2022-25101

A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $1,950 2022-02-24