Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Wbce_cms
(Wbce)Repositories | https://github.com/WBCE/WBCE_CMS |
#Vulnerabilities | 30 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-11-21 | CVE-2022-45012 | A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field. | Wbce_cms | 4.8 | ||
2022-11-21 | CVE-2022-45013 | A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field. | Wbce_cms | 4.8 | ||
2022-11-21 | CVE-2022-45014 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field. | Wbce_cms | 4.8 | ||
2022-11-21 | CVE-2022-45015 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field. | Wbce_cms | 4.8 | ||
2022-11-21 | CVE-2022-45016 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field. | Wbce_cms | 4.8 | ||
2022-11-21 | CVE-2022-45017 | A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field. | Wbce_cms | 4.8 | ||
2023-04-18 | CVE-2023-29855 | WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php. | Wbce_cms | 7.2 | ||
2021-12-09 | CVE-2021-3817 | wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command | Wbce_cms | 9.8 | ||
2022-02-24 | CVE-2022-25099 | A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. | Wbce_cms | 7.8 | ||
2022-02-24 | CVE-2022-25101 | A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. | Wbce_cms | 7.8 |