Записи wintercms
10 опубликованных записей вендора wintercms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 90 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-284 Improper Access Control1
- CWE-97 Improper Neutralization of Server-Side Includes (SSI) Within a Web Page1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-39357Эксплойта нет | Winter vulnerable to Prototype Pollution in Snowboard frameworkwintercms · winter · CWE-1321 | Критическая9,8 | — | 1,1 % | 26 окт. 2022 г. |
39Наблюдать | CVE-2026-27591Эксплойта нет | Winter: Privilege escalation by authenticated backend userswintercms · winter · CWE-284 | Критическая9,9 | — | 0,8 % | 11 мар. 2026 г. |
35Наблюдать | CVE-2024-32003Эксплойта нет | Dusk plugin may allow unfettered user authentication in misconfigured installswintercms · wn-dusk-plugin · CWE-269 | Высокая8,8 | — | 0,7 % | 12 апр. 2024 г. |
33Наблюдать | CVE-2024-54149Эксплойта нет | Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletionwintercms · winter · CWE-184 | Высокая8,4 | — | 0,4 % | 9 дек. 2024 г. |
30Наблюдать | CVE-2023-52085Proof of concept | Winter CMS Local File Inclusion through Server Side Template Injectionwintercms · winter · CWE-22 | Средняя5,4 | — | 30,2 % | 28 дек. 2023 г. |
29Наблюдать | CVE-2024-29686Эксплойта нет | Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted pwintercms · winter · CWE-97 | Высокая7,2 | — | 1,8 % | 29 мар. 2024 г. |
21Наблюдать | CVE-2023-52084Эксплойта нет | Winter CMS Stored XSS through Backend ColorPicker FormWidgetwintercms · winter · CWE-79 | Средняя5,4 | — | 0,3 % | 28 дек. 2023 г. |
20Наблюдать | CVE-2023-37269Proof of concept | Winter CMS vulnerable to stored XSS through privileged upload of SVG filewintercms · winter · CWE-79 | Средняя4,8 | — | 2,7 % | 7 июл. 2023 г. |
19Наблюдать | CVE-2023-52083Эксплойта нет | Stored XSS through privileged upload of Media Manager file followed by renamingwintercms · winter · CWE-79 | Средняя4,8 | — | 0,3 % | 28 дек. 2023 г. |
14Наблюдать | CVE-2026-22254Эксплойта нет | Winter Affected by Stored Cross-Site Scripting (XSS) in Asset Managerwintercms · winter · CWE-79 | Низкая3,5 | — | 0,3 % | 6 февр. 2026 г. |
- CVE-2022-3935739Наблюдать
Winter vulnerable to Prototype Pollution in Snowboard framework
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wintercms · winter26 окт. 2022 г.
- CVE-2026-2759139Наблюдать
Winter: Privilege escalation by authenticated backend users
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %wintercms · winter11 мар. 2026 г.
- CVE-2024-3200335Наблюдать
Dusk plugin may allow unfettered user authentication in misconfigured installs
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wintercms · wn-dusk-plugin12 апр. 2024 г.
- CVE-2024-5414933Наблюдать
Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %wintercms · winter9 дек. 2024 г.
- CVE-2023-5208530Наблюдать
Winter CMS Local File Inclusion through Server Side Template Injection
СредняяCVSS 5,4Proof of conceptEPSS 30 %wintercms · winter28 дек. 2023 г.
- CVE-2024-2968629Наблюдать
Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted p
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %wintercms · winter29 мар. 2024 г.
- CVE-2023-5208421Наблюдать
Winter CMS Stored XSS through Backend ColorPicker FormWidget
СредняяCVSS 5,4Эксплойта нетEPSS 0 %wintercms · winter28 дек. 2023 г.
- CVE-2023-3726920Наблюдать
Winter CMS vulnerable to stored XSS through privileged upload of SVG file
СредняяCVSS 4,8Proof of conceptEPSS 3 %wintercms · winter7 июл. 2023 г.
- CVE-2023-5208319Наблюдать
Stored XSS through privileged upload of Media Manager file followed by renaming
СредняяCVSS 4,8Эксплойта нетEPSS 0 %wintercms · winter28 дек. 2023 г.
- CVE-2026-2225414Наблюдать
Winter Affected by Stored Cross-Site Scripting (XSS) in Asset Manager
НизкаяCVSS 3,5Эксплойта нетEPSS 0 %wintercms · winter6 февр. 2026 г.