WonderCMS kayıtları
wondercms üreticisine ait 37 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %2,7
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
37 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2020-35313Kavram kanıtı | A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remwondercms · wondercms · CWE-918 | Kritik9,8 | — | %45,2 | 20 Nis 2021 |
47Planlayın | CVE-2020-35314Kavram kanıtı | A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackerwondercms · wondercms · CWE-78 | Kritik9,8 | — | %26,9 | 20 Nis 2021 |
40Planlayın | CVE-2023-41425Silahlaştırılmış | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted scripwondercms · wondercms · CWE-79 | Orta6,1 | — | %54,3 | 7 Kas 2023 |
40Planlayın | CVE-2014-8704İstismar yok | Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via awondercms · wondercms · CWE-22 | Kritik9,8 | — | %2,0 | 17 Mar 2017 |
39İzleyin | CVE-2014-8705İstismar yok | PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URwondercms · wondercms · CWE-20 | Kritik9,8 | — | %1,5 | 17 Mar 2017 |
38İzleyin | CVE-2024-32340İstismar yok | A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or wondercms · wondercms · CWE-79 | Kritik9,6 | — | %0,7 | 17 Nis 2024 |
37İzleyin | CVE-2017-14521Kavram kanıtı | In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.wondercms · wondercms · CWE-434 | Yüksek8,8 | — | %7,3 | 26 Oca 2018 |
35İzleyin | CVE-2018-14387İstismar yok | An issue was discovered in WonderCMS before 2.5.2.wondercms · wondercms · CWE-384 | Yüksek8,8 | — | %1,6 | 18 Tem 2018 |
35İzleyin | CVE-2017-7951İstismar yok | WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.wondercms · wondercms · CWE-352 | Yüksek8,8 | — | %0,6 | 20 Nis 2017 |
32İzleyin | CVE-2017-14523Kavram kanıtı | WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack.wondercms · wondercms · CWE-74 | Yüksek7,5 | — | %8,0 | 26 Oca 2018 |
32İzleyin | CVE-2024-27561İstismar yok | A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the applicwondercms · wondercms · CWE-918 | Yüksek8,1 | — | %0,6 | 5 Mar 2024 |
30İzleyin | CVE-2014-8701İstismar yok | Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed pawondercms · wondercms · CWE-200 | Yüksek7,5 | — | %1,5 | 17 Mar 2017 |
27İzleyin | CVE-2019-5956İstismar yok | Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.wondercms · wondercms · CWE-22 | Orta6,5 | — | %1,9 | 12 Eyl 2019 |
26İzleyin | CVE-2025-57055Kavram kanıtı | WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality.wondercms · wondercms · CWE-918 | Orta6,5 | — | %0,4 | 17 Eyl 2025 |
24İzleyin | CVE-2017-14522İstismar yok | In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript.wondercms · wondercms · CWE-79 | Orta6,1 | — | %1,2 | 26 Oca 2018 |
24İzleyin | CVE-2014-8703İstismar yok | Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.wondercms · wondercms · CWE-79 | Orta6,1 | — | %0,8 | 17 Mar 2017 |
24İzleyin | CVE-2022-43332Kavram kanıtı | A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted paylowondercms · wondercms · CWE-79 | Orta6,1 | — | %0,6 | 17 Kas 2022 |
24İzleyin | CVE-2024-32337İstismar yok | A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or wondercms · wondercms · CWE-79 | Orta6,1 | — | %0,4 | 17 Nis 2024 |
24İzleyin | CVE-2024-32339İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scriptswondercms · wondercms · CWE-79 | Orta6,1 | — | %0,4 | 17 Nis 2024 |
23İzleyin | CVE-2024-32745İstismar yok | A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or wondercms · wondercms · CWE-79 | Orta5,9 | — | %0,3 | 17 Nis 2024 |
22İzleyin | CVE-2024-32743İstismar yok | A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or wondercms · wondercms · CWE-79 | Orta5,5 | — | %0,4 | 17 Nis 2024 |
21İzleyin | CVE-2020-29469Kavram kanıtı | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component.wondercms · wondercms · CWE-79 | Orta5,4 | — | %1,4 | 30 Ara 2020 |
21İzleyin | CVE-2014-8702İstismar yok | Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, whicwondercms · wondercms · CWE-200 | Orta5,3 | — | %1,4 | 17 Mar 2017 |
21İzleyin | CVE-2020-29233Kavram kanıtı | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component.wondercms · wondercms · CWE-79 | Orta5,4 | — | %1,3 | 30 Ara 2020 |
21İzleyin | CVE-2021-42233İstismar yok | The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability.wondercms · wondercms · CWE-79 | Orta5,4 | — | %0,9 | 23 May 2022 |
- CVE-2020-3531353Planlayın
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows rem
KritikCVSS 9,8Kavram kanıtıEPSS %45wondercms · wondercms20 Nis 2021
- CVE-2020-3531447Planlayın
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attacker
KritikCVSS 9,8Kavram kanıtıEPSS %27wondercms · wondercms20 Nis 2021
- CVE-2023-4142540Planlayın
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted scrip
OrtaCVSS 6,1SilahlaştırılmışEPSS %54wondercms · wondercms7 Kas 2023
- CVE-2014-870440Planlayın
Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a
KritikCVSS 9,8İstismar yokEPSS %2wondercms · wondercms17 Mar 2017
- CVE-2014-870539İzleyin
PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a UR
KritikCVSS 9,8İstismar yokEPSS %1wondercms · wondercms17 Mar 2017
- CVE-2024-3234038İzleyin
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or
KritikCVSS 9,6İstismar yokEPSS %1wondercms · wondercms17 Nis 2024
- CVE-2017-1452137İzleyin
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
YüksekCVSS 8,8Kavram kanıtıEPSS %7wondercms · wondercms26 Oca 2018
- CVE-2018-1438735İzleyin
An issue was discovered in WonderCMS before 2.5.2.
YüksekCVSS 8,8İstismar yokEPSS %2wondercms · wondercms18 Tem 2018
- CVE-2017-795135İzleyin
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.
YüksekCVSS 8,8İstismar yokEPSS %1wondercms · wondercms20 Nis 2017
- CVE-2017-1452332İzleyin
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack.
YüksekCVSS 7,5Kavram kanıtıEPSS %8wondercms · wondercms26 Oca 2018
- CVE-2024-2756132İzleyin
A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the applic
YüksekCVSS 8,1İstismar yokEPSS %1wondercms · wondercms5 Mar 2024
- CVE-2014-870130İzleyin
Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed pa
YüksekCVSS 7,5İstismar yokEPSS %1wondercms · wondercms17 Mar 2017
- CVE-2019-595627İzleyin
Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.
OrtaCVSS 6,5İstismar yokEPSS %2wondercms · wondercms12 Eyl 2019
- CVE-2025-5705526İzleyin
WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality.
OrtaCVSS 6,5Kavram kanıtıEPSS %0wondercms · wondercms17 Eyl 2025
- CVE-2017-1452224İzleyin
In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript.
OrtaCVSS 6,1İstismar yokEPSS %1wondercms · wondercms26 Oca 2018
- CVE-2014-870324İzleyin
Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.
OrtaCVSS 6,1İstismar yokEPSS %1wondercms · wondercms17 Mar 2017
- CVE-2022-4333224İzleyin
A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted paylo
OrtaCVSS 6,1Kavram kanıtıEPSS %1wondercms · wondercms17 Kas 2022
- CVE-2024-3233724İzleyin
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or
OrtaCVSS 6,1İstismar yokEPSS %0wondercms · wondercms17 Nis 2024
- CVE-2024-3233924İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts
OrtaCVSS 6,1İstismar yokEPSS %0wondercms · wondercms17 Nis 2024
- CVE-2024-3274523İzleyin
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or
OrtaCVSS 5,9İstismar yokEPSS %0wondercms · wondercms17 Nis 2024
- CVE-2024-3274322İzleyin
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or
OrtaCVSS 5,5İstismar yokEPSS %0wondercms · wondercms17 Nis 2024
- CVE-2020-2946921İzleyin
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component.
OrtaCVSS 5,4Kavram kanıtıEPSS %1wondercms · wondercms30 Ara 2020
- CVE-2014-870221İzleyin
Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, whic
OrtaCVSS 5,3İstismar yokEPSS %1wondercms · wondercms17 Mar 2017
- CVE-2020-2923321İzleyin
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component.
OrtaCVSS 5,4Kavram kanıtıEPSS %1wondercms · wondercms30 Ara 2020
- CVE-2021-4223321İzleyin
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability.
OrtaCVSS 5,4İstismar yokEPSS %1wondercms · wondercms23 May 2022