wintercms Summary
Latest vulnerabilities published by wintercms
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
File Upload Widget Vulnerability in Winter CMS by Winter
CVE-2026-54256WintercmsWinter5.4MEDIUMUnauthorized Access in Winter CMS Theme Editor by Winter
CVE-2026-32639WintercmsWinter6.8MEDIUMSQL Injection Vulnerability in Winter CMS Backend Filter Widget by Winter
CVE-2026-32593WintercmsWinter5.9MEDIUMStored Cross-Site Scripting Vulnerability in Winter CMS by Winter
CVE-2026-32258WintercmsWinter8.1HIGHStored Cross-Site Scripting in Winter CMS Affects Multiple Backend Pages
CVE-2026-32257WintercmsWinter8.1HIGHUnauthorized Access Vulnerability in Winter CMS by Winter
CVE-2026-35445WintercmsWinter7.1HIGHTwig Sandbox Escape Vulnerability in Winter CMS by Winter
CVE-2026-79774WintercmsWinter9.3CRITICALLocal File Inclusion Vulnerability in Winter CMS by Winter
CVE-2026-79773WintercmsWinter6.9MEDIUMAccount Escalation Vulnerability in Winter CMS by Winter
CVE-2026-27591WintercmsWinter10CRITICALSecurity Flaw in Winter CMS Allows Unsafe SVG Uploads by Unauthorized Users
CVE-2026-22254WintercmsWinterNONEDusk plugin vulnerability allows unauthorized access to user accounts
CVE-2024-32003WintercmsWn-dusk-plugin8.8HIGHWinter CMS Local File Inclusion through Server Side Template Injection
CVE-2023-52085wintercmswinterEPSS 30%3.3LOWStored XSS through privileged upload of Media Manager file followed by renaming
CVE-2023-52083wintercmswinter2LOWWinter CMS Stored XSS through Backend ColorPicker FormWidget
CVE-2023-52084WintercmsWinter2LOWWinter CMS vulnerable to stored XSS through privileged upload of SVG file
CVE-2023-37269WintercmsWinter2LOWWinter vulnerable to Prototype Pollution in Snowboard framework
CVE-2022-39357WintercmsWinter8.1HIGH