ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-36579
Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).

Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).

NVD description · AI analysis pending
8.8<1% PoC
  • wellcms wellcms
CVE-2020-21005
WellCMS 2.0 beta3 is vulnerable to File Upload.

WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.

NVD description · AI analysis pending
6.5<1% PoC
  • wellcms wellcms