File Upload Widget Vulnerability in Winter CMS by Winter
CVE-2026-54256

5.4MEDIUM

Key Information:

Vendor

Wintercms

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-54256?

In Winter CMS, versions up to and including 1.2.12, a vulnerability in the backend FileUpload form widget allows authenticated users to exploit the system. This occurs through the unvalidated handling of file_id POST parameters, which enables unauthorized modification of attachment records by targeting arbitrary attachments. Affected users can alter attachment titles and descriptions without proper authorization checks, as the widget incorrectly resolves file attachments. The issue can be exploited with an authenticated backend session, where CSRF tokens remain enforced, providing further security challenges. This flaw has been addressed in version 1.2.13.

Affected Version(s)

winter < 1.2.13

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.