wolfcms records
16 published records for vendor wolfcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-20 Improper Input Validation2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2015-6567Proof of concept | Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanagewolfcms · wolf cms · CWE-20 | High8.8 | — | 10.8% | Apr 14, 2017 |
38Monitor | CVE-2015-6568Proof of concept | Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanagewolfcms · wolf cms · CWE-20 | High8.8 | — | 10.6% | Apr 14, 2017 |
27Monitor | CVE-2018-8814Proof of concept | Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requestwolfcms · wolf cms · CWE-352 | Medium6.5 | — | 3.0% | Apr 4, 2018 |
27Monitor | CVE-2012-1897Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication wolfcms · wolf cms · CWE-352 | Medium6.8 | — | 1.2% | Oct 1, 2012 |
24Monitor | CVE-2019-10646No exploit | Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add).wolfcms · wolf cms · CWE-79 | Medium6.1 | — | 0.9% | Mar 29, 2019 |
24Monitor | CVE-2019-25070No exploit | WolfCMS User Add cross site scriptingwolfcms · wolf cms · CWE-80 | Medium6.1 | — | 0.8% | Jun 9, 2022 |
21Monitor | CVE-2017-11611Proof of concept | Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks.wolfcms · wolf cms · CWE-79 | Medium5.4 | — | 0.9% | Sep 8, 2017 |
21Monitor | CVE-2018-1000084No exploit | WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can resulwolfcms · wolf cms · CWE-79 | Medium5.4 | — | 0.6% | Mar 13, 2018 |
20Monitor | CVE-2018-8813Proof of concept | Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect userwolfcms · wolf cms · CWE-601 | Medium4.8 | — | 3.2% | Apr 4, 2018 |
19Monitor | CVE-2018-18824No exploit | WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.wolfcms · wolf cms · CWE-79 | Medium4.8 | — | 1.0% | Apr 25, 2019 |
19Monitor | CVE-2018-18823No exploit | WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.wolfcms · wolf cms · CWE-79 | Medium4.8 | — | 1.0% | Apr 25, 2019 |
19Monitor | CVE-2018-6890Proof of concept | Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/page/edit/3.wolfcms · wolf cms · CWE-79 | Medium4.8 | — | 0.7% | Feb 22, 2018 |
19Monitor | CVE-2012-1932No exploit | A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via twolfcms · wolf cms · CWE-79 | Medium4.8 | — | 0.7% | Feb 19, 2020 |
19Monitor | CVE-2018-14837No exploit | Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.wolfcms · wolf cms · CWE-79 | Medium4.8 | — | 0.7% | Aug 10, 2018 |
19Monitor | CVE-2018-15842No exploit | WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.wolfcms · wolf cms · CWE-79 | Medium4.8 | — | 0.7% | Aug 25, 2018 |
19Monitor | CVE-2018-1000087No exploit | WolfCMS version version 0.8.3.1 contains a Reflected Cross Site Scripting vulnerability in "Create New File" and "Create New Directory" inpuwolfcms · wolf cms · CWE-79 | Medium4.8 | — | 0.6% | Mar 13, 2018 |
- CVE-2015-656738Monitor
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanage
HighCVSS 8.8Proof of conceptEPSS 11%wolfcms · wolf cmsApr 14, 2017
- CVE-2015-656838Monitor
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanage
HighCVSS 8.8Proof of conceptEPSS 11%wolfcms · wolf cmsApr 14, 2017
- CVE-2018-881427Monitor
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for request
MediumCVSS 6.5Proof of conceptEPSS 3%wolfcms · wolf cmsApr 4, 2018
- CVE-2012-189727Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication
MediumCVSS 6.8Proof of conceptEPSS 1%wolfcms · wolf cmsOct 1, 2012
- CVE-2019-1064624Monitor
Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add).
MediumCVSS 6.1No exploitEPSS 1%wolfcms · wolf cmsMar 29, 2019
- CVE-2019-2507024Monitor
WolfCMS User Add cross site scripting
MediumCVSS 6.1No exploitEPSS 1%wolfcms · wolf cmsJun 9, 2022
- CVE-2017-1161121Monitor
Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks.
MediumCVSS 5.4Proof of conceptEPSS 1%wolfcms · wolf cmsSep 8, 2017
- CVE-2018-100008421Monitor
WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can resul
MediumCVSS 5.4No exploitEPSS 1%wolfcms · wolf cmsMar 13, 2018
- CVE-2018-881320Monitor
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect user
MediumCVSS 4.8Proof of conceptEPSS 3%wolfcms · wolf cmsApr 4, 2018
- CVE-2018-1882419Monitor
WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
MediumCVSS 4.8No exploitEPSS 1%wolfcms · wolf cmsApr 25, 2019
- CVE-2018-1882319Monitor
WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
MediumCVSS 4.8No exploitEPSS 1%wolfcms · wolf cmsApr 25, 2019
- CVE-2018-689019Monitor
Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/page/edit/3.
MediumCVSS 4.8Proof of conceptEPSS 1%wolfcms · wolf cmsFeb 22, 2018
- CVE-2012-193219Monitor
A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via t
MediumCVSS 4.8No exploitEPSS 1%wolfcms · wolf cmsFeb 19, 2020
- CVE-2018-1483719Monitor
Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.
MediumCVSS 4.8No exploitEPSS 1%wolfcms · wolf cmsAug 10, 2018
- CVE-2018-1584219Monitor
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
MediumCVSS 4.8No exploitEPSS 1%wolfcms · wolf cmsAug 25, 2018
- CVE-2018-100008719Monitor
WolfCMS version version 0.8.3.1 contains a Reflected Cross Site Scripting vulnerability in "Create New File" and "Create New Directory" inpu
MediumCVSS 4.8No exploitEPSS 1%wolfcms · wolf cmsMar 13, 2018