📦 Wtcms

by Wtcms Project

🔍 What is Wtcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-48237

CRITICAL CVSS 9.8 Oct 25, 2024

WTCMS 1.0 has an incorrect access control vulnerability in the HomebaseController that allows attackers to bypass authentication and authorization mechanisms. This affects all installations of WTCMS 1...

CVE-2025-13786

HIGH CVSS 7.3 Nov 30, 2025

This CVE describes a remote code injection vulnerability in taosir WTCMS that allows attackers to execute arbitrary code by manipulating the 'content' parameter in the fetch function. The vulnerabilit...

CVE-2025-13782

HIGH CVSS 7.3 Nov 30, 2025

This CVE describes an SQL injection vulnerability in taosir WTCMS's SlideController component. Attackers can exploit this to execute arbitrary SQL commands on the database. All installations up to com...

CVE-2025-13783

MEDIUM CVSS 6.3 Nov 30, 2025

This CVE describes a SQL injection vulnerability in taosir WTCMS's comment administration component. Attackers can remotely exploit this flaw by manipulating comment IDs to execute arbitrary SQL comma...

CVE-2024-48239

MEDIUM CVSS 4.8 Oct 25, 2024

This vulnerability in WTCMS 1.0 allows attackers to inject malicious scripts via the plupload method in AssetController.class.php due to improper input sanitization. This affects all users of WTCMS 1....