Skip to content
Noroxi

wintercms records

10 published records for vendor wintercms.

All records

10 records
  • Winter vulnerable to Prototype Pollution in Snowboard framework

    CriticalCVSS 9.8No exploitEPSS 1%

    wintercms · winterOct 26, 2022

  • Winter: Privilege escalation by authenticated backend users

    CriticalCVSS 9.9No exploitEPSS 1%

    wintercms · winterMar 11, 2026

  • Dusk plugin may allow unfettered user authentication in misconfigured installs

    HighCVSS 8.8No exploitEPSS 1%

    wintercms · wn-dusk-pluginApr 12, 2024

  • Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion

    HighCVSS 8.4No exploitEPSS 0%

    wintercms · winterDec 9, 2024

  • Winter CMS Local File Inclusion through Server Side Template Injection

    MediumCVSS 5.4Proof of conceptEPSS 30%

    wintercms · winterDec 28, 2023

  • Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted p

    HighCVSS 7.2No exploitEPSS 2%

    wintercms · winterMar 29, 2024

  • Winter CMS Stored XSS through Backend ColorPicker FormWidget

    MediumCVSS 5.4No exploitEPSS 0%

    wintercms · winterDec 28, 2023

  • Winter CMS vulnerable to stored XSS through privileged upload of SVG file

    MediumCVSS 4.8Proof of conceptEPSS 3%

    wintercms · winterJul 7, 2023

  • Stored XSS through privileged upload of Media Manager file followed by renaming

    MediumCVSS 4.8No exploitEPSS 0%

    wintercms · winterDec 28, 2023

  • Winter Affected by Stored Cross-Site Scripting (XSS) in Asset Manager

    LowCVSS 3.5No exploitEPSS 0%

    wintercms · winterFeb 6, 2026