Skip to content
Noroxi

wcms records

17 published records for vendor wcms.

All records

17 records
  • In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish par

    CriticalCVSS 9.8No exploitEPSS 20%

    wcms · wcmsMay 22, 2023

  • Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php

    CriticalCVSS 9.8No exploitEPSS 2%

    wcms · wcmsJun 27, 2023

  • wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension a

    HighCVSS 8.8No exploitEPSS 2%

    wcms · wcmsApr 20, 2019

  • Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename p

    HighCVSS 8.6No exploitEPSS 2%

    wcms · wcmsApr 7, 2021

  • Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via

    HighCVSS 8.3No exploitEPSS 1%

    wcms · wcmsApr 7, 2021

  • Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application vi

    HighCVSS 8.3No exploitEPSS 1%

    wcms · wcmsApr 7, 2021

  • WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html UR

    HighCVSS 8.1No exploitEPSS 1%

    wcms · wcmsJul 23, 2019

  • CVE-2025-3800
    27Monitor

    WCMS AnonymousController.php sql injection

    MediumCVSS 6.9No exploitEPSS 1%

    wcms · wcmsApr 19, 2025

  • CVE-2025-3799
    27Monitor

    WCMS AnonymousController.php sql injection

    MediumCVSS 6.9No exploitEPSS 1%

    wcms · wcmsApr 19, 2025

  • CVE-2025-5149
    25Monitor

    WCMS Login getallcon getMemberByUid improper authentication

    MediumCVSS 6.3No exploitEPSS 1%

    wcms · wcmsMay 25, 2025

  • Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML via the pagename para

    MediumCVSS 6.1No exploitEPSS 1%

    wcms · wcmsApr 7, 2021

  • A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inject arbitrary web scr

    MediumCVSS 6.1No exploitEPSS 1%

    wcms · wcmsApr 7, 2021

  • Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via

    MediumCVSS 5.3No exploitEPSS 1%

    wcms · wcmsApr 7, 2021

  • CVE-2024-8875
    21Monitor

    vedees wcms finder.php path traversal

    MediumCVSS 5.3No exploitEPSS 1%

    wcms · wcmsSep 15, 2024

  • CVE-2025-2978
    21Monitor

    WCMS Article Publishing Page CKEditor unrestricted upload

    MediumCVSS 5.3No exploitEPSS 1%

    wcms · wcmsMar 31, 2025

  • CVE-2025-3798
    20Monitor

    WCMS Advertisement Image AdvadminController.php sub unrestricted upload

    MediumCVSS 5.1No exploitEPSS 0%

    wcms · wcmsApr 19, 2025

  • CVE-2025-2979
    19Monitor

    WCMS Registration setregister cross site scripting

    MediumCVSS 4.8No exploitEPSS 0%

    wcms · wcmsMar 31, 2025