Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wondercms MEDIUM 6.5
CVE-2025-57055

WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator c…

No fix yet
Fix from $1,600 2025-09-17
Wondercms HIGH 7.2
CVE-2025-3123

A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleActio…

No fix yet
Fix from $1,950 2025-04-02
Wondercms MEDIUM 5.4
CVE-2024-41304

An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafte…

No fix yet
Fix from $1,600 2024-07-30
Wondercms CRITICAL 9.6
CVE-2024-32340

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via …

No fix yet
Fix from $2,300 2024-04-17
Wondercms MEDIUM 6.1
CVE-2024-32337

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via …

No fix yet
Fix from $1,600 2024-04-17
Wondercms MEDIUM 6.1
CVE-2024-32339

Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML …

No fix yet
Fix from $1,600 2024-04-17
Wondercms MEDIUM 5.9
CVE-2024-32745

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via …

No fix yet
Fix from $1,600 2024-04-17
Wondercms MEDIUM 5.5
CVE-2024-32743

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via …

No fix yet
Fix from $1,600 2024-04-17
Wondercms MEDIUM 5.4
CVE-2024-32338

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via …

No fix yet
Fix from $1,600 2024-04-17
Wondercms MEDIUM 5.4
CVE-2024-32341

Multiple cross-site scripting (XSS) vulnerabilities in the Home page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML vi…

No fix yet
Fix from $1,600 2024-04-17
Wondercms HIGH 8.1
CVE-2024-27561

A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to …

No fix yet
Fix from $1,950 2024-03-05
Wondercms MEDIUM 5.3
CVE-2024-27563

A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary …

No fix yet
Fix from $1,600 2024-03-05
Wondercms MEDIUM 6.1
CVE-2023-41425EPSS 54%

Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploade…

Fix: after 3.4.2
Fix from $1,600 2023-11-07
Wondercms MEDIUM 6.1
CVE-2022-43332

A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inject…

Mitigation only
Fix from $1,600 2022-11-17
Wondercms CRITICAL 9.8
CVE-2020-35314EPSS 27%

A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to uplo…

No fix yet
Fix from $2,300 2021-04-20
Wondercms CRITICAL 9.8
CVE-2020-35313EPSS 45%

A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attac…

No fix yet
Fix from $2,300 2021-04-20
Wondercms MEDIUM 5.4
CVE-2020-29233

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the X…

No fix yet
Fix from $1,600 2020-12-30
Wondercms MEDIUM 5.4
CVE-2020-29469

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload i…

No fix yet
Fix from $1,600 2020-12-30
Wondercms MEDIUM 6.5
CVE-2019-5956

Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.

Fix: after 2.6.0
Fix from $1,600 2019-09-12
Wondercms HIGH 8.8
CVE-2018-14387

An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identi…

Fix: 2.5.2+
Fix from $1,950 2018-07-18
Wondercms HIGH 8.8
CVE-2017-14521EPSS 7%

In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

No fix yet
Fix from $1,950 2018-01-26
Wondercms HIGH 7.5
CVE-2017-14523EPSS 8%

WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that e…

No fix yet
Fix from $1,950 2018-01-26
Wondercms MEDIUM 6.1
CVE-2017-14522

In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor dispu…

No fix yet
Fix from $1,600 2018-01-26
Wondercms HIGH 8.8
CVE-2017-7951

WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.

Fix: after 2.0.2
Fix from $1,950 2017-04-21
Wondercms CRITICAL 9.8
CVE-2014-8704

Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted …

Mitigation only
Fix from $2,300 2017-03-17
Wondercms CRITICAL 9.8
CVE-2014-8705

PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the …

Patch available
Fix from $2,300 2017-03-17
Wondercms HIGH 7.5
CVE-2014-8701

Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.

No fix yet
Fix from $1,950 2017-03-17
Wondercms MEDIUM 6.1
CVE-2014-8703

Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.

No fix yet
Fix from $1,600 2017-03-17
Wondercms MEDIUM 5.3
CVE-2014-8702

Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals…

No fix yet
Fix from $1,600 2017-03-17