Записи wcms
17 опубликованных записей вендора wcms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-284 Improper Access Control2
- CWE-918 Server-Side Request Forgery (SSRF)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2023-31689Эксплойта нет | In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parwcms · wcms · CWE-434 | Критическая9,8 | — | 20,2 % | 22 мая 2023 г. |
40В плане | CVE-2020-19902Эксплойта нет | Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php wcms · wcms · CWE-22 | Критическая9,8 | — | 1,9 % | 27 июн. 2023 г. |
36Наблюдать | CVE-2019-11377Эксплойта нет | wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension awcms · wcms · CWE-434 | Высокая8,8 | — | 1,7 % | 20 апр. 2019 г. |
35Наблюдать | CVE-2020-24136Эксплойта нет | Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename pwcms · wcms · CWE-22 | Высокая8,6 | — | 2,2 % | 7 апр. 2021 г. |
33Наблюдать | CVE-2020-24140Эксплойта нет | Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application viawcms · wcms · CWE-918 | Высокая8,3 | — | 1,2 % | 7 апр. 2021 г. |
33Наблюдать | CVE-2020-24139Эксплойта нет | Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application viwcms · wcms · CWE-918 | Высокая8,3 | — | 1,1 % | 7 апр. 2021 г. |
32Наблюдать | CVE-2019-14240Эксплойта нет | WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URwcms · wcms · CWE-22 | Высокая8,1 | — | 0,8 % | 23 июл. 2019 г. |
27Наблюдать | CVE-2025-3800Эксплойта нет | WCMS AnonymousController.php sql injectionwcms · wcms · CWE-74 | Средняя6,9 | — | 0,6 % | 19 апр. 2025 г. |
27Наблюдать | CVE-2025-3799Эксплойта нет | WCMS AnonymousController.php sql injectionwcms · wcms · CWE-74 | Средняя6,9 | — | 0,5 % | 19 апр. 2025 г. |
25Наблюдать | CVE-2025-5149Эксплойта нет | WCMS Login getallcon getMemberByUid improper authenticationwcms · wcms · CWE-287 | Средняя6,3 | — | 0,6 % | 25 мая 2025 г. |
24Наблюдать | CVE-2020-24138Эксплойта нет | Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML via the pagename parawcms · wcms · CWE-79 | Средняя6,1 | — | 0,9 % | 7 апр. 2021 г. |
24Наблюдать | CVE-2020-24135Эксплойта нет | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inject arbitrary web scrwcms · wcms · CWE-79 | Средняя6,1 | — | 0,9 % | 7 апр. 2021 г. |
21Наблюдать | CVE-2020-24137Эксплойта нет | Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via wcms · wcms · CWE-22 | Средняя5,3 | — | 1,4 % | 7 апр. 2021 г. |
21Наблюдать | CVE-2024-8875Эксплойта нет | vedees wcms finder.php path traversalwcms · wcms · CWE-22 | Средняя5,3 | — | 0,9 % | 15 сент. 2024 г. |
21Наблюдать | CVE-2025-2978Эксплойта нет | WCMS Article Publishing Page CKEditor unrestricted uploadwcms · wcms · CWE-284 | Средняя5,3 | — | 0,5 % | 31 мар. 2025 г. |
20Наблюдать | CVE-2025-3798Эксплойта нет | WCMS Advertisement Image AdvadminController.php sub unrestricted uploadwcms · wcms · CWE-284 | Средняя5,1 | — | 0,5 % | 19 апр. 2025 г. |
19Наблюдать | CVE-2025-2979Эксплойта нет | WCMS Registration setregister cross site scriptingwcms · wcms · CWE-79 | Средняя4,8 | — | 0,4 % | 31 мар. 2025 г. |
- CVE-2023-3168945В плане
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish par
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %wcms · wcms22 мая 2023 г.
- CVE-2020-1990240В плане
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %wcms · wcms27 июн. 2023 г.
- CVE-2019-1137736Наблюдать
wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension a
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %wcms · wcms20 апр. 2019 г.
- CVE-2020-2413635Наблюдать
Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename p
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %wcms · wcms7 апр. 2021 г.
- CVE-2020-2414033Наблюдать
Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %wcms · wcms7 апр. 2021 г.
- CVE-2020-2413933Наблюдать
Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application vi
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %wcms · wcms7 апр. 2021 г.
- CVE-2019-1424032Наблюдать
WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html UR
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %wcms · wcms23 июл. 2019 г.
- CVE-2025-380027Наблюдать
WCMS AnonymousController.php sql injection
СредняяCVSS 6,9Эксплойта нетEPSS 1 %wcms · wcms19 апр. 2025 г.
- CVE-2025-379927Наблюдать
WCMS AnonymousController.php sql injection
СредняяCVSS 6,9Эксплойта нетEPSS 1 %wcms · wcms19 апр. 2025 г.
- CVE-2025-514925Наблюдать
WCMS Login getallcon getMemberByUid improper authentication
СредняяCVSS 6,3Эксплойта нетEPSS 1 %wcms · wcms25 мая 2025 г.
- CVE-2020-2413824Наблюдать
Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML via the pagename para
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wcms · wcms7 апр. 2021 г.
- CVE-2020-2413524Наблюдать
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inject arbitrary web scr
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wcms · wcms7 апр. 2021 г.
- CVE-2020-2413721Наблюдать
Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wcms · wcms7 апр. 2021 г.
- CVE-2024-887521Наблюдать
vedees wcms finder.php path traversal
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wcms · wcms15 сент. 2024 г.
- CVE-2025-297821Наблюдать
WCMS Article Publishing Page CKEditor unrestricted upload
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wcms · wcms31 мар. 2025 г.
- CVE-2025-379820Наблюдать
WCMS Advertisement Image AdvadminController.php sub unrestricted upload
СредняяCVSS 5,1Эксплойта нетEPSS 0 %wcms · wcms19 апр. 2025 г.
- CVE-2025-297919Наблюдать
WCMS Registration setregister cross site scripting
СредняяCVSS 4,8Эксплойта нетEPSS 0 %wcms · wcms31 мар. 2025 г.