Winter CMS 是一个基于 Laravel PHP 框架构建的内容管理系统。在 1.2.13 版本之前的版本中,后台未对通过表单回传(postback) POST 字段提交的处理器(handler)名称进行校验,导致经过身份验证的后台用户能够调用任意的控制器方法,包括受保护的(protected)、私有的(private)以及以“action”为前缀的方法。虽然 AJAX 请求会校验处理器名称是否符合 格式,但通过 postback 路径时,系统将提交的 值直接传递给处理器调度器,而未进行类似的检查。因此,任
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-32257 | 8.1 HIGH | Winter: Stored XSS through Brand Settings custom styles |
| CVE-2026-32258 | 8.1 HIGH | Winter: Stored XSS through Editor Settings custom styles |
| CVE-2026-32639 | 6.8 MEDIUM | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and |
| CVE-2026-32593 | 5.9 MEDIUM | Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax |
| CVE-2026-54256 | 5.4 MEDIUM | Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attach |
| CVE-2026-63179 | 4.9 MEDIUM | Winter: Local File Inclusion through @import directives in LESS compilation of backend cus |
No comments yet