SQL Injection Vulnerability in Winter CMS Backend Filter Widget by Winter
CVE-2026-32593
5.9MEDIUM
What is CVE-2026-32593?
Winter CMS, developed on the Laravel PHP framework, is susceptible to a SQL injection vulnerability in its backend Filter widget. In versions up to and including 1.2.12, an authenticated user can exploit a crafted AJAX request when the numberrange scope type is configured with a conditions key. This flaw allows the user to inject arbitrary SQL commands, leading to unauthorized access to database contents. It is important to note that this vulnerability requires specific configurations which are not present in the default Winter CMS installation, necessitating third-party plugins that register a numberrange filter scope with a conditions key for exploitation. This issue has been addressed in version 1.2.13.
Affected Version(s)
winter < 1.2.13
