📦 Wcms

by Wcms

🔍 What is Wcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-19902

CRITICAL CVSS 9.8 Jun 27, 2023

CVE-2020-19902 is a critical directory traversal vulnerability in Cryptoprof WCMS v0.3.2 that allows remote attackers to execute arbitrary code via the wex/cssjs.php parameter. This affects all system...

CVE-2023-31689

CRITICAL CVSS 9.8 May 22, 2023

This vulnerability in Wcms 0.3.2 allows unauthenticated attackers to upload arbitrary files and execute malicious code through crafted requests to the /wcms/wex/html.php endpoint. Attackers can achiev...

CVE-2025-3799

HIGH CVSS 7.3 Apr 19, 2025

This critical SQL injection vulnerability in WCMS 11 allows remote attackers to execute arbitrary SQL commands by manipulating email/username parameters in the AnonymousController.php file. Attackers ...

CVE-2020-24139

HIGH CVSS 8.3 Apr 7, 2021

CVE-2020-24139 is a server-side request forgery (SSRF) vulnerability in Wcms 0.3.2 that allows attackers to make arbitrary HTTP requests from the vulnerable server via the path parameter in wex/cssjs....

CVE-2025-5149

MEDIUM CVSS 5.6 May 25, 2025

This CVE describes an improper authentication vulnerability in WCMS that allows attackers to bypass authentication mechanisms by manipulating the uid parameter in the getMemberByUid function. The vuln...