WBCE kayıtları
wbce üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %10
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-434 Unrestricted Upload of File with Dangerous Type6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-331 Insufficient Entropy1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2022-46020Kavram kanıtı | WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.wbce · wbce cms · CWE-434 | Kritik9,8 | — | %39,0 | 20 Ara 2022 |
51Planlayın | CVE-2021-3817Kavram kanıtı | SQL Injection in wbce/wbce_cmswbce · wbce cms · CWE-89 | Kritik9,8 | — | %38,4 | 9 Ara 2021 |
41Planlayın | CVE-2023-39796Kavram kanıtı | SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via wbce · wbce cms · CWE-89 | Kritik9,8 | — | %6,1 | 10 Kas 2023 |
39İzleyin | CVE-2025-67504İstismar yok | WBCE CMS has Weak Random Number Generator in Password Generation Functionwbce · wbce cms · CWE-331 | Kritik9,8 | — | %0,5 | 9 Ara 2025 |
37İzleyin | CVE-2025-65950Kavram kanıtı | WBCE CMS is Vulnerable to Time-Based Blind SQL Injection through groups[] Parameterwbce · wbce cms · CWE-89 | Kritik9,4 | — | %0,5 | 10 Ara 2025 |
35İzleyin | CVE-2017-2119İstismar yok | Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.wbce · wbce cms · CWE-22 | Yüksek8,6 | — | %3,5 | 28 Nis 2017 |
34İzleyin | CVE-2022-50936İstismar yok | WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)wbce · wbce cms · CWE-434 | Yüksek8,7 | — | %0,9 | 13 Oca 2026 |
34İzleyin | CVE-2025-34506İstismar yok | WBCE CMS 1.6.3 Authenticated Remote Code Execution via Module Uploadwbce · wbce cms · CWE-434 | Yüksek8,6 | — | %0,9 | 11 Ara 2025 |
34İzleyin | CVE-2024-58283İstismar yok | WBCE CMS 1.6.2 Remote Code Execution via Elfinder File Uploadwbce · wbce cms · CWE-434 | Yüksek8,7 | — | %0,7 | 10 Ara 2025 |
34İzleyin | CVE-2025-65094Kavram kanıtı | WBCE CMS is Vulnerable to Privilege Escalation via Group ID Manipulation (IDOR)wbce · wbce cms · CWE-266 | Yüksek8,7 | — | %0,4 | 19 Kas 2025 |
31İzleyin | CVE-2022-25101İstismar yok | A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP filewbce · wbce cms | Yüksek7,8 | — | %1,2 | 24 Şub 2022 |
31İzleyin | CVE-2022-25099İstismar yok | A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.wbce · wbce cms | Yüksek7,8 | — | %1,2 | 24 Şub 2022 |
30İzleyin | CVE-2022-4006İstismar yok | WBCE CMS Header class.login.php increase_attempts excessive authenticationwbce · wbce cms · CWE-400 | Yüksek7,5 | — | %0,8 | 15 Kas 2022 |
28İzleyin | CVE-2019-17575İstismar yok | A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier.wbce · wbce cms · CWE-706 | Yüksek7,2 | — | %1,4 | 14 Eki 2019 |
28İzleyin | CVE-2017-2120İstismar yok | SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands vwbce · wbce cms · CWE-89 | Yüksek7,2 | — | %1,3 | 28 Nis 2017 |
28İzleyin | CVE-2023-29855İstismar yok | WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php.wbce · wbce cms · CWE-77 | Yüksek7,2 | — | %1,2 | 18 Nis 2023 |
28İzleyin | CVE-2022-45039İstismar yok | An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crawbce · wbce cms · CWE-434 | Yüksek7,2 | — | %1,1 | 25 Kas 2022 |
28İzleyin | CVE-2023-38947İstismar yok | An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary codewbce · wbce cms · CWE-434 | Yüksek7,2 | — | %0,5 | 3 Ağu 2023 |
28İzleyin | CVE-2023-53901İstismar yok | WBCE CMS 1.6.1 Cross-Site Scripting and Open Redirect Vulnerabilitywbce · wbce cms · CWE-601 | Yüksek7,1 | — | %0,3 | 16 Ara 2025 |
25İzleyin | CVE-2025-66204Kavram kanıtı | WBCE CMS allows brute-force protection bypass using X-Forwarded-For headerwbce · wbce cms · CWE-307 | Orta6,3 | — | %0,5 | 8 Ara 2025 |
24İzleyin | CVE-2017-2118İstismar yok | Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspeciwbce · wbce cms · CWE-79 | Orta6,1 | — | %1,2 | 28 Nis 2017 |
24İzleyin | CVE-2022-28477İstismar yok | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).wbce · wbce cms · CWE-79 | Orta6,1 | — | %1,0 | 28 Nis 2022 |
21İzleyin | CVE-2022-30073Kavram kanıtı | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.wbce · wbce cms · CWE-79 | Orta5,4 | — | %1,6 | 17 May 2022 |
21İzleyin | CVE-2022-45037Kavram kanıtı | A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts orwbce · wbce cms · CWE-79 | Orta5,4 | — | %1,1 | 25 Kas 2022 |
21İzleyin | CVE-2022-45038Kavram kanıtı | A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts wbce · wbce cms · CWE-79 | Orta5,4 | — | %1,1 | 25 Kas 2022 |
- CVE-2022-4602051Planlayın
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
KritikCVSS 9,8Kavram kanıtıEPSS %39wbce · wbce cms20 Ara 2022
- CVE-2021-381751Planlayın
SQL Injection in wbce/wbce_cms
KritikCVSS 9,8Kavram kanıtıEPSS %38wbce · wbce cms9 Ara 2021
- CVE-2023-3979641Planlayın
SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via
KritikCVSS 9,8Kavram kanıtıEPSS %6wbce · wbce cms10 Kas 2023
- CVE-2025-6750439İzleyin
WBCE CMS has Weak Random Number Generator in Password Generation Function
KritikCVSS 9,8İstismar yokEPSS %1wbce · wbce cms9 Ara 2025
- CVE-2025-6595037İzleyin
WBCE CMS is Vulnerable to Time-Based Blind SQL Injection through groups[] Parameter
KritikCVSS 9,4Kavram kanıtıEPSS %1wbce · wbce cms10 Ara 2025
- CVE-2017-211935İzleyin
Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
YüksekCVSS 8,6İstismar yokEPSS %4wbce · wbce cms28 Nis 2017
- CVE-2022-5093634İzleyin
WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)
YüksekCVSS 8,7İstismar yokEPSS %1wbce · wbce cms13 Oca 2026
- CVE-2025-3450634İzleyin
WBCE CMS 1.6.3 Authenticated Remote Code Execution via Module Upload
YüksekCVSS 8,6İstismar yokEPSS %1wbce · wbce cms11 Ara 2025
- CVE-2024-5828334İzleyin
WBCE CMS 1.6.2 Remote Code Execution via Elfinder File Upload
YüksekCVSS 8,7İstismar yokEPSS %1wbce · wbce cms10 Ara 2025
- CVE-2025-6509434İzleyin
WBCE CMS is Vulnerable to Privilege Escalation via Group ID Manipulation (IDOR)
YüksekCVSS 8,7Kavram kanıtıEPSS %0wbce · wbce cms19 Kas 2025
- CVE-2022-2510131İzleyin
A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file
YüksekCVSS 7,8İstismar yokEPSS %1wbce · wbce cms24 Şub 2022
- CVE-2022-2509931İzleyin
A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.
YüksekCVSS 7,8İstismar yokEPSS %1wbce · wbce cms24 Şub 2022
- CVE-2022-400630İzleyin
WBCE CMS Header class.login.php increase_attempts excessive authentication
YüksekCVSS 7,5İstismar yokEPSS %1wbce · wbce cms15 Kas 2022
- CVE-2019-1757528İzleyin
A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier.
YüksekCVSS 7,2İstismar yokEPSS %1wbce · wbce cms14 Eki 2019
- CVE-2017-212028İzleyin
SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands v
YüksekCVSS 7,2İstismar yokEPSS %1wbce · wbce cms28 Nis 2017
- CVE-2023-2985528İzleyin
WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php.
YüksekCVSS 7,2İstismar yokEPSS %1wbce · wbce cms18 Nis 2023
- CVE-2022-4503928İzleyin
An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a cra
YüksekCVSS 7,2İstismar yokEPSS %1wbce · wbce cms25 Kas 2022
- CVE-2023-3894728İzleyin
An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code
YüksekCVSS 7,2İstismar yokEPSS %1wbce · wbce cms3 Ağu 2023
- CVE-2023-5390128İzleyin
WBCE CMS 1.6.1 Cross-Site Scripting and Open Redirect Vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0wbce · wbce cms16 Ara 2025
- CVE-2025-6620425İzleyin
WBCE CMS allows brute-force protection bypass using X-Forwarded-For header
OrtaCVSS 6,3Kavram kanıtıEPSS %0wbce · wbce cms8 Ara 2025
- CVE-2017-211824İzleyin
Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspeci
OrtaCVSS 6,1İstismar yokEPSS %1wbce · wbce cms28 Nis 2017
- CVE-2022-2847724İzleyin
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %1wbce · wbce cms28 Nis 2022
- CVE-2022-3007321İzleyin
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.
OrtaCVSS 5,4Kavram kanıtıEPSS %2wbce · wbce cms17 May 2022
- CVE-2022-4503721İzleyin
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or
OrtaCVSS 5,4Kavram kanıtıEPSS %1wbce · wbce cms25 Kas 2022
- CVE-2022-4503821İzleyin
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts
OrtaCVSS 5,4Kavram kanıtıEPSS %1wbce · wbce cms25 Kas 2022