Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-32593— Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax

Quick assessment

Affected
wintercms winter
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Winter CMS 是基于 Laravel PHP 框架构建的内容管理系统。在包括 1.2.12 及之前的版本中,后台的过滤器组件在“数范围”(numberrange)作用域类型且配置了“条件”(conditions)键时,存在 SQL 注入漏洞,允许已认证的后台用户注入任意 SQL 语句。该作用域的过滤值在未进行参数绑定的情况下被直接拼接到条件语句中,因此,拥有使用此作用域及配置的列表视图访问权限的用户,可通过该过滤器的 AJAX 处理器提供特制输入,从而读取任意数据库内容。由于 Winter CMS 内置的后

CVSS 5.9 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
wintercms winter < 1.2.13 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-32593

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
Source: CVE Program / CVE List V5
Vulnerability Description
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configured with a conditions key, allowing an authenticated backend user to inject arbitrary SQL. The scope's filter values are interpolated into the conditions statement without parameter binding, so a user with access to a list view whose filter uses this scope and configuration can supply crafted input through the filter's AJAX handler and read arbitrary database contents. No built-in Winter CMS backend views use this scope type and configuration combination, so exploitation requires a third-party plugin to have registered a numberrange filter scope with a conditions key, and a vanilla installation without such plugins is not affected. This issue is fixed in version 1.2.13.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wintercms winter < 1.2.13 -

II. Public POCs for CVE-2026-32593

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-32593

登录查看更多情报信息。

Patches & Fixes for CVE-2026-32593 (1)

Vendor Advisories for CVE-2026-32593 (1)

Same Patch Batch · wintercms · 2026-08-26 · 7 CVEs total

CVE-2026-32257 8.1 HIGH Winter: Stored XSS through Brand Settings custom styles
CVE-2026-32258 8.1 HIGH Winter: Stored XSS through Editor Settings custom styles
CVE-2026-35445 7.1 HIGH Winter: Authenticated backend users can bypass Users controller permission checks
CVE-2026-32639 6.8 MEDIUM Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and
CVE-2026-54256 5.4 MEDIUM Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attach
CVE-2026-63179 4.9 MEDIUM Winter: Local File Inclusion through @import directives in LESS compilation of backend cus

IV. Related Vulnerabilities

V. Comments for CVE-2026-32593

No comments yet


Leave a comment