Перейти к содержимому
Noroxi

Записи wintercms

10 опубликованных записей вендора wintercms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
90 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

10 записей
  • CVE-2022-39357
    39Наблюдать

    Winter vulnerable to Prototype Pollution in Snowboard framework

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    wintercms · winter26 окт. 2022 г.

  • CVE-2026-27591
    39Наблюдать

    Winter: Privilege escalation by authenticated backend users

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    wintercms · winter11 мар. 2026 г.

  • CVE-2024-32003
    35Наблюдать

    Dusk plugin may allow unfettered user authentication in misconfigured installs

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    wintercms · wn-dusk-plugin12 апр. 2024 г.

  • CVE-2024-54149
    33Наблюдать

    Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    wintercms · winter9 дек. 2024 г.

  • CVE-2023-52085
    30Наблюдать

    Winter CMS Local File Inclusion through Server Side Template Injection

    СредняяCVSS 5,4Proof of conceptEPSS 30 %

    wintercms · winter28 дек. 2023 г.

  • CVE-2024-29686
    29Наблюдать

    Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted p

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    wintercms · winter29 мар. 2024 г.

  • CVE-2023-52084
    21Наблюдать

    Winter CMS Stored XSS through Backend ColorPicker FormWidget

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    wintercms · winter28 дек. 2023 г.

  • CVE-2023-37269
    20Наблюдать

    Winter CMS vulnerable to stored XSS through privileged upload of SVG file

    СредняяCVSS 4,8Proof of conceptEPSS 3 %

    wintercms · winter7 июл. 2023 г.

  • CVE-2023-52083
    19Наблюдать

    Stored XSS through privileged upload of Media Manager file followed by renaming

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    wintercms · winter28 дек. 2023 г.

  • CVE-2026-22254
    14Наблюдать

    Winter Affected by Stored Cross-Site Scripting (XSS) in Asset Manager

    НизкаяCVSS 3,5Эксплойта нетEPSS 0 %

    wintercms · winter6 февр. 2026 г.