Local File Inclusion Vulnerability in Winter CMS by Winter
CVE-2026-79773

6.9MEDIUM

Key Information:

Vendor

Wintercms

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79773?

Winter CMS versions before 1.2.13 are susceptible to a local file inclusion vulnerability in the JavascriptImporter filter. This flaw allows authenticated users with the 'cms.manage_assets' permission to exploit the vulnerability by including directives in theme JavaScript assets. By doing so, they can access server-readable files, such as sensitive configuration files, leveraging the combine route to deliver the output to unauthenticated users, which could lead to exposure of critical data like application keys and database credentials.

Affected Version(s)

winter 0 < 1.2.13

winter 1.2.13

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

elmahy111
.