Перейти к содержимому
Noroxi

Записи WonderCMS

37 опубликованных записей вендора wondercms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 2,7 %
Pre-auth RCE
10
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

37 записей
  • CVE-2020-35313
    53В плане

    A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows rem

    КритическаяCVSS 9,8Proof of conceptEPSS 45 %

    wondercms · wondercms20 апр. 2021 г.

  • CVE-2020-35314
    47В плане

    A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attacker

    КритическаяCVSS 9,8Proof of conceptEPSS 27 %

    wondercms · wondercms20 апр. 2021 г.

  • CVE-2023-41425
    40В плане

    Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted scrip

    СредняяCVSS 6,1Готовый эксплойтEPSS 54 %

    wondercms · wondercms7 нояб. 2023 г.

  • CVE-2014-8704
    40В плане

    Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    wondercms · wondercms17 мар. 2017 г.

  • CVE-2014-8705
    39Наблюдать

    PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a UR

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    wondercms · wondercms17 мар. 2017 г.

  • CVE-2024-32340
    38Наблюдать

    A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    wondercms · wondercms17 апр. 2024 г.

  • CVE-2017-14521
    37Наблюдать

    In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

    ВысокаяCVSS 8,8Proof of conceptEPSS 7 %

    wondercms · wondercms26 янв. 2018 г.

  • CVE-2018-14387
    35Наблюдать

    An issue was discovered in WonderCMS before 2.5.2.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    wondercms · wondercms18 июл. 2018 г.

  • CVE-2017-7951
    35Наблюдать

    WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    wondercms · wondercms20 апр. 2017 г.

  • CVE-2017-14523
    32Наблюдать

    WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack.

    ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

    wondercms · wondercms26 янв. 2018 г.

  • CVE-2024-27561
    32Наблюдать

    A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the applic

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    wondercms · wondercms5 мар. 2024 г.

  • CVE-2014-8701
    30Наблюдать

    Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed pa

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    wondercms · wondercms17 мар. 2017 г.

  • CVE-2019-5956
    27Наблюдать

    Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    wondercms · wondercms12 сент. 2019 г.

  • CVE-2025-57055
    26Наблюдать

    WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality.

    СредняяCVSS 6,5Proof of conceptEPSS 0 %

    wondercms · wondercms17 сент. 2025 г.

  • CVE-2017-14522
    24Наблюдать

    In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    wondercms · wondercms26 янв. 2018 г.

  • CVE-2014-8703
    24Наблюдать

    Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    wondercms · wondercms17 мар. 2017 г.

  • CVE-2022-43332
    24Наблюдать

    A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted paylo

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    wondercms · wondercms17 нояб. 2022 г.

  • CVE-2024-32337
    24Наблюдать

    A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    wondercms · wondercms17 апр. 2024 г.

  • CVE-2024-32339
    24Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    wondercms · wondercms17 апр. 2024 г.

  • CVE-2024-32745
    23Наблюдать

    A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    wondercms · wondercms17 апр. 2024 г.

  • CVE-2024-32743
    22Наблюдать

    A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    wondercms · wondercms17 апр. 2024 г.

  • CVE-2020-29469
    21Наблюдать

    WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component.

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    wondercms · wondercms30 дек. 2020 г.

  • CVE-2014-8702
    21Наблюдать

    Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, whic

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    wondercms · wondercms17 мар. 2017 г.

  • CVE-2020-29233
    21Наблюдать

    WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component.

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    wondercms · wondercms30 дек. 2020 г.

  • CVE-2021-42233
    21Наблюдать

    The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    wondercms · wondercms23 мая 2022 г.