Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wcms HIGH 8.1
CVE-2025-5149

A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of th…

Fix: after 8.3.11
Fix from $1,950 2025-05-25
Wcms CRITICAL 9.8
CVE-2025-3800

A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/cont…

No fix yet
Fix from $2,300 2025-04-19
Wcms CRITICAL 9.8
CVE-2025-3799

A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousControl…

No fix yet
Fix from $2,300 2025-04-19
Wcms HIGH 7.2
CVE-2025-3798

A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminContr…

No fix yet
Fix from $1,950 2025-04-19
Wcms CRITICAL 9.8
CVE-2025-2978

A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?arti…

No fix yet
Fix from $2,300 2025-03-31
Wcms MEDIUM 5.4
CVE-2025-2979

A vulnerability classified as problematic has been found in WCMS 11. This affects an unknown part of the file /index.php?anonymous/setregister of the…

No fix yet
Fix from $1,600 2025-03-31
Wcms CRITICAL 9.1
CVE-2024-8875

A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /…

Fix: 0.3.2+
Fix from $2,300 2024-09-15
Wcms CRITICAL 9.8
CVE-2020-19902

Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.

No fix yet
Fix from $2,300 2023-06-27
Wcms CRITICAL 9.8
CVE-2023-31689EPSS 20%

In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter an…

No fix yet
Fix from $2,300 2023-05-22
Wcms HIGH 8.3
CVE-2020-24139

Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application via the pat…

No fix yet
Fix from $1,950 2021-04-07
Wcms HIGH 8.3
CVE-2020-24140

Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the page…

No fix yet
Fix from $1,950 2021-04-07
Wcms MEDIUM 5.3
CVE-2020-24137

Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the path …

Mitigation only
Fix from $1,600 2021-04-07
Wcms MEDIUM 6.1
CVE-2020-24135

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inject arbitrary web script and H…

No fix yet
Fix from $1,600 2021-04-07
Wcms HIGH 8.6
CVE-2020-24136

Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter …

No fix yet
Fix from $1,950 2021-04-07
Wcms MEDIUM 6.1
CVE-2020-24138

Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML via the pagename parameter to …

No fix yet
Fix from $1,600 2021-04-07
Wcms HIGH 8.1
CVE-2019-14240

WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.

Mitigation only
Fix from $1,950 2019-07-23
Wcms HIGH 8.8
CVE-2019-11377

wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according …

No fix yet
Fix from $1,950 2019-04-20