Winter 是一个基于 Laravel PHP 框架的免费、开源的内容管理系统(CMS)。在 1.2.13 版本之前,具有 权限的后端用户通过“品牌设置”中的“样式”字段提供的自定义 CSS,会经过 LESS 解析器进行编译,并在每个后端页面渲染时未经过任何消毒处理(sanitization),从而导致针对后端用户的存储型跨站脚本(Stored XSS)漏洞。该问题已在 1.2.13 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32258 | 8.1 HIGH | Winter: Stored XSS through Editor Settings custom styles |
| CVE-2026-35445 | 7.1 HIGH | Winter: Authenticated backend users can bypass Users controller permission checks |
| CVE-2026-32639 | 6.8 MEDIUM | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and |
| CVE-2026-32593 | 5.9 MEDIUM | Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax |
| CVE-2026-54256 | 5.4 MEDIUM | Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attach |
| CVE-2026-63179 | 4.9 MEDIUM | Winter: Local File Inclusion through @import directives in LESS compilation of backend cus |
No comments yet