📦 Wbce Cms

by Wbce

🔍 What is Wbce Cms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-67504

CRITICAL CVSS 9.1 Dec 9, 2025

WBCE CMS versions 1.6.4 and below use PHP's non-cryptographically secure rand() function to generate passwords, making them predictable. Attackers can brute-force or predict passwords for new accounts...

CVE-2023-39796

CRITICAL CVSS 9.8 Nov 10, 2023

This SQL injection vulnerability in WBCE CMS's miniform module allows remote unauthenticated attackers to execute arbitrary SQL commands via the DB_RECORD_TABLE parameter. Attackers can potentially re...

CVE-2021-3817

CRITICAL CVSS 9.8 Dec 9, 2021

CVE-2021-3817 is an SQL injection vulnerability in WBCE CMS that allows attackers to execute arbitrary SQL commands. This can lead to authentication bypass, data theft, or complete system compromise. ...

CVE-2022-50936

HIGH CVSS 8.8 Jan 13, 2026

This vulnerability allows authenticated attackers to execute arbitrary PHP code on WBCE CMS servers by uploading malicious droplets through the admin panel. Attackers can craft specially designed zip ...

CVE-2025-34506

HIGH CVSS 8.8 Dec 11, 2025

This vulnerability allows authenticated administrators in WBCE CMS to upload malicious ZIP modules containing PHP reverse shell code, leading to remote code execution. Attackers who compromise admin c...

CVE-2024-58283

HIGH CVSS 8.8 Dec 10, 2025

This vulnerability allows authenticated attackers to upload malicious PHP files through the Elfinder file manager in WBCE CMS version 1.6.2, leading to remote code execution. Attackers can upload web ...

CVE-2025-65950

HIGH CVSS 8.8 Dec 10, 2025

WBCE CMS versions 1.6.4 and below contain a SQL injection vulnerability in the user management module. Authenticated users with permission to modify other users can execute arbitrary SQL queries, pote...

CVE-2025-66204

HIGH CVSS 8.1 Dec 9, 2025

WBCE CMS version 1.6.4 has a brute-force protection bypass vulnerability where attackers can modify the X-Forwarded-For header to reset login attempt counters, allowing unlimited password guessing. Th...

CVE-2025-65094

HIGH CVSS 8.8 Nov 19, 2025

This vulnerability allows low-privileged users in WBCE CMS to escalate their privileges to full administrative access by manipulating the groups[] parameter in user update requests. Server-side valida...

CVE-2023-38947

HIGH CVSS 7.2 Aug 3, 2023

This vulnerability allows attackers to upload arbitrary PHP files to WBCE CMS through the /languages/install.php component, leading to remote code execution. It affects WBCE CMS version 1.6.1. Attacke...

CVE-2023-29855

HIGH CVSS 7.2 Apr 18, 2023

WBCE CMS 1.5.3 contains a command injection vulnerability in admin/languages/install.php that allows authenticated attackers to execute arbitrary commands on the server. This affects all WBCE CMS inst...

CVE-2022-25099

HIGH CVSS 7.8 Feb 24, 2022

This vulnerability in WBCE CMS allows attackers to upload and execute arbitrary PHP code through the languages management interface. It affects all WBCE CMS v1.5.2 installations with default configura...

CVE-2023-53909

MEDIUM CVSS 5.4 Dec 17, 2025

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability where authenticated users can upload malicious SVG files containing JavaScript. When victims access these uploaded files, the JavaSc...

CVE-2023-53910

MEDIUM CVSS 5.4 Dec 17, 2025

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious JavaScript into page content via the WYSIWYG editor. This can lead to session hi...