İçeriğe atla
Noroxi

wintercms kayıtları

wintercms üreticisine ait 10 yayımlanmış kayıt.

Tüm kayıtlar

10 kayıt
  • CVE-2022-39357
    39İzleyin

    Winter vulnerable to Prototype Pollution in Snowboard framework

    KritikCVSS 9,8İstismar yokEPSS %1

    wintercms · winter26 Eki 2022

  • CVE-2026-27591
    39İzleyin

    Winter: Privilege escalation by authenticated backend users

    KritikCVSS 9,9İstismar yokEPSS %1

    wintercms · winter11 Mar 2026

  • CVE-2024-32003
    35İzleyin

    Dusk plugin may allow unfettered user authentication in misconfigured installs

    YüksekCVSS 8,8İstismar yokEPSS %1

    wintercms · wn-dusk-plugin12 Nis 2024

  • CVE-2024-54149
    33İzleyin

    Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion

    YüksekCVSS 8,4İstismar yokEPSS %0

    wintercms · winter9 Ara 2024

  • CVE-2023-52085
    30İzleyin

    Winter CMS Local File Inclusion through Server Side Template Injection

    OrtaCVSS 5,4Kavram kanıtıEPSS %30

    wintercms · winter28 Ara 2023

  • CVE-2024-29686
    29İzleyin

    Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted p

    YüksekCVSS 7,2İstismar yokEPSS %2

    wintercms · winter29 Mar 2024

  • CVE-2023-52084
    21İzleyin

    Winter CMS Stored XSS through Backend ColorPicker FormWidget

    OrtaCVSS 5,4İstismar yokEPSS %0

    wintercms · winter28 Ara 2023

  • CVE-2023-37269
    20İzleyin

    Winter CMS vulnerable to stored XSS through privileged upload of SVG file

    OrtaCVSS 4,8Kavram kanıtıEPSS %3

    wintercms · winter7 Tem 2023

  • CVE-2023-52083
    19İzleyin

    Stored XSS through privileged upload of Media Manager file followed by renaming

    OrtaCVSS 4,8İstismar yokEPSS %0

    wintercms · winter28 Ara 2023

  • CVE-2026-22254
    14İzleyin

    Winter Affected by Stored Cross-Site Scripting (XSS) in Asset Manager

    DüşükCVSS 3,5İstismar yokEPSS %0

    wintercms · winter6 Şub 2026