Vulnerabilities
40 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-50936 | WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload. NVD description · AI analysis pending | 8.7 | <1% | PoC |
| — | |
| CVE-2023-53910 +1 in the same advisory: …53909 | WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through the WYSIWYG editor. Attackers can submit POST requests to /wbce/modules/wysiwyg/save.php with malicious script content in the content parameter to execute JavaScript when users view the affected page. NVD description · AI analysis pending | 5.1 | <1% | PoC ×2 |
| — | |
| CVE-2023-53901 | WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a crafted HTML file with CSS-based keylogging techniques to intercept password characters through background image requests. NVD description · AI analysis pending | 7.1 | <1% | PoC |
| — | |
| CVE-2025-34506 | WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed. NVD description · AI analysis pending | 8.6 | <1% | PoC ×3 |
| — | |
| CVE-2025-65950 +1 in the same advisory: …58283 | WBCE CMS is a content management system. WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be escalated to a full database compromise, data exfiltration, effectively bypassing all security controls. The vulnerability exists in the admin/users/save.php script, which handles updates to user profiles. The script improperly processes the groups[] parameter sent from the user edit form. This issue is fixed in version 1.6.5. NVD description · AI analysis pending | 9.4 group max | <1% | PoC |
| — | |
| CVE-2025-67504 +1 in the same advisory: …66204 | WBCE CMS is a content management system. WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account compromise or privilege escalation if these passwords are used for new accounts or password resets. The vulnerability is fixed in version 1.6.5. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2025-65094 | WBCE CMS is a content management system. WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the groups[] parameter in the /admin/users/save.php request. The UI restricts users to assigning only their existing group, but server-side validation is missing, allowing attackers to overwrite their group membership and obtain full administrative access. This results in a complete compromise of the CMS. This issue has been patched in version 1.6.4. NVD description · AI analysis pending | 8.7 | <1% | PoC |
| — | |
| CVE-2023-39796 | SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter. NVD description · AI analysis pending | 9.8 | 6% |
| — | ||
| CVE-2023-46054 | Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_foot Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-43871 | A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS). A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS). NVD description · AI analysis pending | 5.4 | <1% | PoC ×2 |
| — | |
| CVE-2023-38947 | An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP f An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2023-29855 | WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php. WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2022-46020 | WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. NVD description · AI analysis pending | 9.8 | 39% | PoC |
| — | |
| CVE-2022-45039 | An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file. An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file. NVD description · AI analysis pending | 7.2 group max | 1% | PoC |
| — | |
| CVE-2022-45017 | A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2022-4006 | A vulnerability, which was classified as problematic, has been found in WBCE CMS. A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The name of the patch is d394ba39a7bfeb31eda797b6195fd90ef74b2e75. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213716. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2022-30073 +1 in the same advisory: …30072 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. NVD description · AI analysis pending | 5.4 | 2% | PoC ×2 |
| — | |
| CVE-2022-28477 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2022-25101 +1 in the same advisory: …25099 | A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. NVD description · AI analysis pending | 7.8 | 1% | PoC |
| — | |
| CVE-2021-3817 | wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command NVD description · AI analysis pending | 9.8 | 38% | PoC ×2 |
| — | |
| CVE-2019-17575 | A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extension. (For example: place PHP code in a .jpg file, and then change the file's base name to filename.ph and change the file's extension to p. Because of concatenation, the name is then treated as filename.php.) At the result, remote attackers can execute arbitrary PHP code. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2018-6313 | Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a dif Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a different issue than CVE-2017-2118. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2017-1000213 | WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2017-2119 | Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors. Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors. NVD description · AI analysis pending | 8.6 group max | 4% |
| — |