SQL Injection Vulnerability in Winter CMS Backend Filter Widget by Winter
CVE-2026-32593

5.9MEDIUM

Key Information:

Vendor

Wintercms

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-32593?

Winter CMS, developed on the Laravel PHP framework, is susceptible to a SQL injection vulnerability in its backend Filter widget. In versions up to and including 1.2.12, an authenticated user can exploit a crafted AJAX request when the numberrange scope type is configured with a conditions key. This flaw allows the user to inject arbitrary SQL commands, leading to unauthorized access to database contents. It is important to note that this vulnerability requires specific configurations which are not present in the default Winter CMS installation, necessitating third-party plugins that register a numberrange filter scope with a conditions key for exploitation. This issue has been addressed in version 1.2.13.

Affected Version(s)

winter < 1.2.13

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.