Product:

Wbce_cms

(Wbce)
Repositories https://github.com/WBCE/WBCE_CMS
#Vulnerabilities 30
Date Id Summary Products Score Patch Annotated
2022-04-28 CVE-2022-28477 WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). Wbce_cms 6.1
2022-05-17 CVE-2022-30073 WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. Wbce_cms 5.4
2022-05-17 CVE-2022-30072 WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters. Wbce_cms 5.4
2022-11-15 CVE-2022-4006 A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The name of the patch is d394ba39a7bfeb31eda797b6195fd90ef74b2e75. It is recommended to apply a patch to fix this issue. The... Wbce_cms 7.5
2022-11-25 CVE-2022-45036 A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field. Wbce_cms 5.4
2022-11-25 CVE-2022-45037 A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field. Wbce_cms 5.4
2022-11-25 CVE-2022-45038 A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field. Wbce_cms 5.4
2022-11-25 CVE-2022-45039 An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file. Wbce_cms 7.2
2022-11-25 CVE-2022-45040 A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field. Wbce_cms 5.4
2022-12-20 CVE-2022-46020 WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. Wbce_cms 9.8