Vulnerability index

Browse CVEs

24 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-57055 WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator c… Wondercms No fix yet Fix from $1,6002025-09-17 HIGH 7.2 CVE-2025-3123 A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleActio… Wondercms No fix yet Fix from $1,9502025-04-02 MEDIUM 5.4 CVE-2024-41304 An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafte… Wondercms No fix yet Fix from $1,6002024-07-30 CRITICAL 9.6 CVE-2024-32340 A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via … Wondercms No fix yet Fix from $2,3002024-04-17 MEDIUM 6.1 CVE-2024-32337 A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via … Wondercms No fix yet Fix from $1,6002024-04-17 MEDIUM 6.1 CVE-2024-32339 Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML … Wondercms No fix yet Fix from $1,6002024-04-17 MEDIUM 5.9 CVE-2024-32745 A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via … Wondercms No fix yet Fix from $1,6002024-04-17 MEDIUM 5.5 CVE-2024-32743 A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via … Wondercms No fix yet Fix from $1,6002024-04-17 MEDIUM 5.4 CVE-2024-32338 A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via … Wondercms No fix yet Fix from $1,6002024-04-17 MEDIUM 5.4 CVE-2024-32341 Multiple cross-site scripting (XSS) vulnerabilities in the Home page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML vi… Wondercms No fix yet Fix from $1,6002024-04-17 HIGH 8.1 CVE-2024-27561 A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to … Wondercms No fix yet Fix from $1,9502024-03-05 MEDIUM 5.3 CVE-2024-27563 A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary … Wondercms No fix yet Fix from $1,6002024-03-05 MEDIUM 6.1 CVE-2022-43332 A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inject… Wondercms Mitigation only Fix from $1,6002022-11-17 CRITICAL 9.8 CVE-2020-35314EPSS 27% A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to uplo… Wondercms No fix yet Fix from $2,3002021-04-20 CRITICAL 9.8 CVE-2020-35313EPSS 45% A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attac… Wondercms No fix yet Fix from $2,3002021-04-20 MEDIUM 5.4 CVE-2020-29233 WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the X… Wondercms No fix yet Fix from $1,6002020-12-30 MEDIUM 5.4 CVE-2020-29469 WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload i… Wondercms No fix yet Fix from $1,6002020-12-30 HIGH 8.8 CVE-2017-14521EPSS 7% In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. Wondercms No fix yet Fix from $1,9502018-01-26 HIGH 7.5 CVE-2017-14523EPSS 8% WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that e… Wondercms No fix yet Fix from $1,9502018-01-26 MEDIUM 6.1 CVE-2017-14522 In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor dispu… Wondercms No fix yet Fix from $1,6002018-01-26 CRITICAL 9.8 CVE-2014-8704 Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted … Wondercms Mitigation only Fix from $2,3002017-03-17 HIGH 7.5 CVE-2014-8701 Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password. Wondercms No fix yet Fix from $1,9502017-03-17 MEDIUM 6.1 CVE-2014-8703 Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML. Wondercms No fix yet Fix from $1,6002017-03-17 MEDIUM 5.3 CVE-2014-8702 Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals… Wondercms No fix yet Fix from $1,6002017-03-17