Winter CMS 是基于 Laravel PHP 框架构建的内容管理系统。在包括 1.2.12 及之前的版本中,后台的过滤器组件在“数范围”(numberrange)作用域类型且配置了“条件”(conditions)键时,存在 SQL 注入漏洞,允许已认证的后台用户注入任意 SQL 语句。该作用域的过滤值在未进行参数绑定的情况下被直接拼接到条件语句中,因此,拥有使用此作用域及配置的列表视图访问权限的用户,可通过该过滤器的 AJAX 处理器提供特制输入,从而读取任意数据库内容。由于 Winter CMS 内置的后
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32257 | 8.1 HIGH | Winter: Stored XSS through Brand Settings custom styles |
| CVE-2026-32258 | 8.1 HIGH | Winter: Stored XSS through Editor Settings custom styles |
| CVE-2026-35445 | 7.1 HIGH | Winter: Authenticated backend users can bypass Users controller permission checks |
| CVE-2026-32639 | 6.8 MEDIUM | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and |
| CVE-2026-54256 | 5.4 MEDIUM | Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attach |
| CVE-2026-63179 | 4.9 MEDIUM | Winter: Local File Inclusion through @import directives in LESS compilation of backend cus |
No comments yet