« Volver al listado

Wintercms

Wintercms Winter: vulnerabilidades y CVE

Wintercms Winter tiene 11 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses4
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-32258Alta (8.1)0.38%—26 ago 2026
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup…
CVE-2026-32257Alta (8.1)0.38%—26 ago 2026
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the…
CVE-2026-27591Crítica (9.9)0.77%—11 mar 2026
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of…
CVE-2026-22254Baja (3.5)0.27%—6 feb 2026
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to upload SVGs without…
CVE-2024-54149Alta (8.4)0.42%—9 dic 2024
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access to the CMS templates sections that modify…
CVE-2024-29686Alta (7.2)1.8%—29 mar 2024
Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes…
CVE-2023-52085Media (5.4)30%—29 dic 2023
Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the…
CVE-2023-52084Media (5.4)0.31%—28 dic 2023
Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be rendered unescaped in the backend…
CVE-2023-52083Media (4.8)0.31%—28 dic 2023
Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after uploading. Previously, media manager…
CVE-2023-37269Media (4.8)2.7%—7 jul 2023
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backend.manage_branding` permission can upload SVGs as the application logo. Prior to version 1.2.3, SVG…
CVE-2022-39357Crítica (9.8)1.1%—26 oct 2022
Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript2
  2. T1189 Drive-by Compromise2
  3. T1068 Exploitation for Privilege Escalation1
  4. T1203 Exploitation for Client Execution1
  5. T1210 Exploitation of Remote Services1
  6. T1565 Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Wintercms