Wbce
Wbce CMS: vulnerabilidades y CVE
Wbce CMS tiene 40 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses10
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-50936 | Alta (8.7) | 0.91% | — | 13 ene 2026 | WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload… |
| CVE-2023-53910 | Media (5.1) | 0.33% | — | 17 dic 2025 | WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through the WYSIWYG editor. Attackers can… |
| CVE-2023-53909 | Media (5.1) | 0.33% | — | 17 dic 2025 | WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by uploading crafted SVG files through the media manager. Attackers can upload SVG… |
| CVE-2023-53901 | Alta (7.1) | 0.27% | — | 16 dic 2025 | WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a crafted HTML file with CSS-based keylogging… |
| CVE-2025-34506 | Alta (8.6) | 0.91% | — | 11 dic 2025 | WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded… |
| CVE-2024-58283 | Alta (8.7) | 0.66% | — | 10 dic 2025 | WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload… |
| CVE-2025-65950 | Crítica (9.4) | 0.54% | — | 10 dic 2025 | WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be… |
| CVE-2025-67504 | Crítica (9.8) | 0.52% | — | 9 dic 2025 | WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to… |
| CVE-2025-66204 | Media (6.3) | 0.48% | — | 9 dic 2025 | WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For` on each request, gaining unlimited… |
| CVE-2025-65094 | Alta (8.7) | 0.38% | — | 19 nov 2025 | WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the groups[] parameter in the… |
| CVE-2023-39796 | Crítica (9.8) | 6.1% | — | 10 nov 2023 | SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter. |
| CVE-2023-46054 | Media (5.4) | 0.45% | — | 21 oct 2023 | Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component. |
| CVE-2023-43871 | Media (5.4) | 0.49% | — | 28 sept 2023 | A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS). |
| CVE-2023-38947 | Alta (7.2) | 0.54% | — | 3 ago 2023 | An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file. |
| CVE-2023-29855 | Alta (7.2) | 1.2% | — | 18 abr 2023 | WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php. |
| CVE-2022-46020 | Crítica (9.8) | 39% | — | 20 dic 2022 | WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. |
| CVE-2022-45040 | Media (5.4) | 0.46% | — | 25 nov 2022 | A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field. |
| CVE-2022-45039 | Alta (7.2) | 1.1% | — | 25 nov 2022 | An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file. |
| CVE-2022-45038 | Media (5.4) | 1.1% | — | 25 nov 2022 | A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field. |
| CVE-2022-45037 | Media (5.4) | 1.1% | — | 25 nov 2022 | A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field. |
| CVE-2022-45036 | Media (5.4) | 0.49% | — | 25 nov 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field. |
| CVE-2022-45017 | Media (4.8) | 0.57% | — | 21 nov 2022 | A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field. |
| CVE-2022-45016 | Media (4.8) | 0.53% | — | 21 nov 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field. |
| CVE-2022-45015 | Media (4.8) | 0.53% | — | 21 nov 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field. |
| CVE-2022-45014 | Media (4.8) | 0.53% | — | 21 nov 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field. |
| CVE-2022-45013 | Media (4.8) | 0.53% | — | 21 nov 2022 | A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field. |
| CVE-2022-45012 | Media (4.8) | 0.53% | — | 21 nov 2022 | A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field. |
| CVE-2022-4006 | Alta (7.5) | 0.84% | — | 15 nov 2022 | A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The… |
| CVE-2022-30072 | Media (5.4) | 0.85% | — | 17 may 2022 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters. |
| CVE-2022-30073 | Media (5.4) | 1.6% | — | 17 may 2022 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.