Vulnerabilities in wintercms
18 resultsVexday analysis
Winter CMS apresenta um portfólio reduzido de 9 vulnerabilidades documentadas, sem incidentes de exploração ativa registrada. A fraqueza predominante é injeção cross-site (CWE-79), com apenas 1 falha classificada como crítica, e nenhuma divulgação nos últimos 90 dias, indicando risco contido e sem pressão imediata de remediação.
CVE-2023-52085LOWWinter CMS Local File Inclusion through Server Side Template Injection EPSS 30.2%CVE-2023-37269LOWWinter CMS vulnerable to stored XSS through privileged upload of SVG fileEPSS 2.7%CVE-2022-39357HIGHWinter vulnerable to Prototype Pollution in Snowboard frameworkEPSS 1.1%CVE-2026-79774CRITICALWinter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicyEPSS 0.8%CVE-2026-27591CRITICALWinter: Privilege escalation by authenticated backend usersEPSS 0.8%CVE-2024-32003HIGHDusk plugin may allow unfettered user authentication in misconfigured installsEPSS 0.7%CVE-2026-63179MEDIUMWinter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assetsEPSS 0.5%CVE-2026-79773MEDIUMWinter CMS before 1.2.13 Local File Inclusion via JavaScriptEPSS 0.5%CVE-2026-32639MEDIUMWinter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploadsEPSS 0.5%CVE-2026-35445HIGHWinter: Authenticated backend users can bypass Users controller permission checksEPSS 0.4%CVE-2024-54149HIGHWinter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletionEPSS 0.4%CVE-2026-32257HIGHWinter: Stored XSS through Brand Settings custom stylesEPSS 0.4%CVE-2026-32258HIGHWinter: Stored XSS through Editor Settings custom stylesEPSS 0.4%CVE-2023-52083LOWStored XSS through privileged upload of Media Manager file followed by renamingEPSS 0.3%CVE-2023-52084LOWWinter CMS Stored XSS through Backend ColorPicker FormWidgetEPSS 0.3%CVE-2026-32593MEDIUMWinter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjaxEPSS 0.3%CVE-2026-22254NONEWinter Affected by Stored Cross-Site Scripting (XSS) in Asset ManagerEPSS 0.3%CVE-2026-54256MEDIUMWinter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadataEPSS 0.2%