Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-50936 WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the a… Wbce Cms No fix yet Fix from $1,9502026-01-13 MEDIUM 5.4 CVE-2023-53909 WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by uploading c… Wbce Cms No fix yet Fix from $1,6002025-12-17 MEDIUM 5.4 CVE-2023-53910 WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting s… Wbce Cms No fix yet Fix from $1,6002025-12-17 MEDIUM 6.1 CVE-2023-53901 WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attac… Wbce Cms No fix yet Fix from $1,6002025-12-16 HIGH 8.8 CVE-2025-34506 WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules… Wbce Cms after 1.6.3 Fix from $1,9502025-12-11 HIGH 8.8 CVE-2024-58283 WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the E… Wbce Cms No fix yet Fix from $1,9502025-12-10 HIGH 8.8 CVE-2025-65950 WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with perm… Wbce Cms 1.6.5+ Fix from $1,9502025-12-10 CRITICAL 9.8 CVE-2025-67504 WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand(… Wbce Cms 1.6.5+ Fix from $2,3002025-12-09 HIGH 8.1 CVE-2025-66204 WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter … Wbce Cms 1.6.5+ Fix from $1,9502025-12-09 HIGH 8.8 CVE-2025-65094 WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrator… Wbce Cms 1.6.4+ Fix from $1,9502025-11-19 CRITICAL 9.8 CVE-2023-39796EPSS 6% SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RE… Wbce Cms Mitigation only Fix from $2,3002023-11-10 MEDIUM 5.4 CVE-2023-46054 Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the w… Wbce Cms after 1.6.1 Fix from $1,6002023-10-21 MEDIUM 5.4 CVE-2023-43871 A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS). Wbce Cms No fix yet Fix from $1,6002023-09-28 HIGH 7.2 CVE-2023-38947 An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a cr… Wbce Cms No fix yet Fix from $1,9502023-08-03 HIGH 7.2 CVE-2023-29855 WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php. Wbce Cms No fix yet Fix from $1,9502023-04-18 CRITICAL 9.8 CVE-2022-46020EPSS 39% WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. Wbce Cms No fix yet Fix from $2,3002022-12-20 HIGH 7.2 CVE-2022-45039 An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP … Wbce Cms No fix yet Fix from $1,9502022-11-25 MEDIUM 5.4 CVE-2022-45040 A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or … Wbce Cms No fix yet Fix from $1,6002022-11-25 MEDIUM 5.4 CVE-2022-45036 A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML… Wbce Cms No fix yet Fix from $1,6002022-11-25 MEDIUM 5.4 CVE-2022-45037 A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via… Wbce Cms No fix yet Fix from $1,6002022-11-25 MEDIUM 5.4 CVE-2022-45038 A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML v… Wbce Cms No fix yet Fix from $1,6002022-11-25 HIGH 7.5 CVE-2022-4006 A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the fil… Wbce Cms Patch available Fix from $1,9502022-11-15 MEDIUM 5.4 CVE-2022-30072 WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters. Wbce Cms No fix yet Fix from $1,6002022-05-17 MEDIUM 5.4 CVE-2022-30073 WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. Wbce Cms No fix yet Fix from $1,6002022-05-17 MEDIUM 6.1 CVE-2022-28477 WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). Wbce Cms No fix yet Fix from $1,6002022-04-28 HIGH 7.8 CVE-2022-25099 A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. Wbce Cms No fix yet Fix from $1,9502022-02-24 HIGH 7.8 CVE-2022-25101 A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. Wbce Cms No fix yet Fix from $1,9502022-02-24 CRITICAL 9.8 CVE-2021-3817EPSS 38% wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command Wbce Cms 1.5.2+ Fix from $2,3002021-12-09 HIGH 7.2 CVE-2019-17575 A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin… Wbce Cms after 1.4.0 Fix from $1,9502019-10-14 HIGH 8.6 CVE-2017-2119 Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors. Wbce Cms after 1.1.10 Fix from $1,9502017-04-28