Записи WonderCMS
37 опубликованных записей вендора wondercms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,7 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
37 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2020-35313Proof of concept | A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remwondercms · wondercms · CWE-918 | Критическая9,8 | — | 45,2 % | 20 апр. 2021 г. |
47В плане | CVE-2020-35314Proof of concept | A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackerwondercms · wondercms · CWE-78 | Критическая9,8 | — | 26,9 % | 20 апр. 2021 г. |
40В плане | CVE-2023-41425Готовый эксплойт | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted scripwondercms · wondercms · CWE-79 | Средняя6,1 | — | 54,3 % | 7 нояб. 2023 г. |
40В плане | CVE-2014-8704Эксплойта нет | Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via awondercms · wondercms · CWE-22 | Критическая9,8 | — | 2,0 % | 17 мар. 2017 г. |
39Наблюдать | CVE-2014-8705Эксплойта нет | PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URwondercms · wondercms · CWE-20 | Критическая9,8 | — | 1,5 % | 17 мар. 2017 г. |
38Наблюдать | CVE-2024-32340Эксплойта нет | A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or wondercms · wondercms · CWE-79 | Критическая9,6 | — | 0,7 % | 17 апр. 2024 г. |
37Наблюдать | CVE-2017-14521Proof of concept | In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.wondercms · wondercms · CWE-434 | Высокая8,8 | — | 7,3 % | 26 янв. 2018 г. |
35Наблюдать | CVE-2018-14387Эксплойта нет | An issue was discovered in WonderCMS before 2.5.2.wondercms · wondercms · CWE-384 | Высокая8,8 | — | 1,6 % | 18 июл. 2018 г. |
35Наблюдать | CVE-2017-7951Эксплойта нет | WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.wondercms · wondercms · CWE-352 | Высокая8,8 | — | 0,6 % | 20 апр. 2017 г. |
32Наблюдать | CVE-2017-14523Proof of concept | WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack.wondercms · wondercms · CWE-74 | Высокая7,5 | — | 8,0 % | 26 янв. 2018 г. |
32Наблюдать | CVE-2024-27561Эксплойта нет | A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the applicwondercms · wondercms · CWE-918 | Высокая8,1 | — | 0,6 % | 5 мар. 2024 г. |
30Наблюдать | CVE-2014-8701Эксплойта нет | Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed pawondercms · wondercms · CWE-200 | Высокая7,5 | — | 1,5 % | 17 мар. 2017 г. |
27Наблюдать | CVE-2019-5956Эксплойта нет | Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.wondercms · wondercms · CWE-22 | Средняя6,5 | — | 1,9 % | 12 сент. 2019 г. |
26Наблюдать | CVE-2025-57055Proof of concept | WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality.wondercms · wondercms · CWE-918 | Средняя6,5 | — | 0,4 % | 17 сент. 2025 г. |
24Наблюдать | CVE-2017-14522Эксплойта нет | In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript.wondercms · wondercms · CWE-79 | Средняя6,1 | — | 1,2 % | 26 янв. 2018 г. |
24Наблюдать | CVE-2014-8703Эксплойта нет | Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.wondercms · wondercms · CWE-79 | Средняя6,1 | — | 0,8 % | 17 мар. 2017 г. |
24Наблюдать | CVE-2022-43332Proof of concept | A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted paylowondercms · wondercms · CWE-79 | Средняя6,1 | — | 0,6 % | 17 нояб. 2022 г. |
24Наблюдать | CVE-2024-32337Эксплойта нет | A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or wondercms · wondercms · CWE-79 | Средняя6,1 | — | 0,4 % | 17 апр. 2024 г. |
24Наблюдать | CVE-2024-32339Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scriptswondercms · wondercms · CWE-79 | Средняя6,1 | — | 0,4 % | 17 апр. 2024 г. |
23Наблюдать | CVE-2024-32745Эксплойта нет | A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or wondercms · wondercms · CWE-79 | Средняя5,9 | — | 0,3 % | 17 апр. 2024 г. |
22Наблюдать | CVE-2024-32743Эксплойта нет | A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or wondercms · wondercms · CWE-79 | Средняя5,5 | — | 0,4 % | 17 апр. 2024 г. |
21Наблюдать | CVE-2020-29469Proof of concept | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component.wondercms · wondercms · CWE-79 | Средняя5,4 | — | 1,4 % | 30 дек. 2020 г. |
21Наблюдать | CVE-2014-8702Эксплойта нет | Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, whicwondercms · wondercms · CWE-200 | Средняя5,3 | — | 1,4 % | 17 мар. 2017 г. |
21Наблюдать | CVE-2020-29233Proof of concept | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component.wondercms · wondercms · CWE-79 | Средняя5,4 | — | 1,3 % | 30 дек. 2020 г. |
21Наблюдать | CVE-2021-42233Эксплойта нет | The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability.wondercms · wondercms · CWE-79 | Средняя5,4 | — | 0,9 % | 23 мая 2022 г. |
- CVE-2020-3531353В плане
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows rem
КритическаяCVSS 9,8Proof of conceptEPSS 45 %wondercms · wondercms20 апр. 2021 г.
- CVE-2020-3531447В плане
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attacker
КритическаяCVSS 9,8Proof of conceptEPSS 27 %wondercms · wondercms20 апр. 2021 г.
- CVE-2023-4142540В плане
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted scrip
СредняяCVSS 6,1Готовый эксплойтEPSS 54 %wondercms · wondercms7 нояб. 2023 г.
- CVE-2014-870440В плане
Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %wondercms · wondercms17 мар. 2017 г.
- CVE-2014-870539Наблюдать
PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a UR
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wondercms · wondercms17 мар. 2017 г.
- CVE-2024-3234038Наблюдать
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %wondercms · wondercms17 апр. 2024 г.
- CVE-2017-1452137Наблюдать
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
ВысокаяCVSS 8,8Proof of conceptEPSS 7 %wondercms · wondercms26 янв. 2018 г.
- CVE-2018-1438735Наблюдать
An issue was discovered in WonderCMS before 2.5.2.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %wondercms · wondercms18 июл. 2018 г.
- CVE-2017-795135Наблюдать
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wondercms · wondercms20 апр. 2017 г.
- CVE-2017-1452332Наблюдать
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack.
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %wondercms · wondercms26 янв. 2018 г.
- CVE-2024-2756132Наблюдать
A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the applic
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %wondercms · wondercms5 мар. 2024 г.
- CVE-2014-870130Наблюдать
Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed pa
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %wondercms · wondercms17 мар. 2017 г.
- CVE-2019-595627Наблюдать
Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %wondercms · wondercms12 сент. 2019 г.
- CVE-2025-5705526Наблюдать
WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality.
СредняяCVSS 6,5Proof of conceptEPSS 0 %wondercms · wondercms17 сент. 2025 г.
- CVE-2017-1452224Наблюдать
In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wondercms · wondercms26 янв. 2018 г.
- CVE-2014-870324Наблюдать
Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wondercms · wondercms17 мар. 2017 г.
- CVE-2022-4333224Наблюдать
A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted paylo
СредняяCVSS 6,1Proof of conceptEPSS 1 %wondercms · wondercms17 нояб. 2022 г.
- CVE-2024-3233724Наблюдать
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wondercms · wondercms17 апр. 2024 г.
- CVE-2024-3233924Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wondercms · wondercms17 апр. 2024 г.
- CVE-2024-3274523Наблюдать
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or
СредняяCVSS 5,9Эксплойта нетEPSS 0 %wondercms · wondercms17 апр. 2024 г.
- CVE-2024-3274322Наблюдать
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or
СредняяCVSS 5,5Эксплойта нетEPSS 0 %wondercms · wondercms17 апр. 2024 г.
- CVE-2020-2946921Наблюдать
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component.
СредняяCVSS 5,4Proof of conceptEPSS 1 %wondercms · wondercms30 дек. 2020 г.
- CVE-2014-870221Наблюдать
Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, whic
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wondercms · wondercms17 мар. 2017 г.
- CVE-2020-2923321Наблюдать
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component.
СредняяCVSS 5,4Proof of conceptEPSS 1 %wondercms · wondercms30 дек. 2020 г.
- CVE-2021-4223321Наблюдать
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %wondercms · wondercms23 мая 2022 г.