Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wintercms — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting wintercms. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WinterCMS serves as a flexible PHP content management system for building websites and applications. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its nine recorded CVEs. The platform's modular architecture introduces potential attack surfaces through plugins and themes. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities suggests developers should implement strict input validation, principle of least privilege configurations, and keep the system updated to mitigate risks associated with its historically vulnerable components.

Top products by wintercms: winter wn-dusk-plugin
CVE ID Title CVSS Severity Published
CVE-2026-63179 Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets — winter CWE-22 4.9 Medium 2026-08-26
CVE-2026-54256 Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata — winter CWE-284 5.4 Medium 2026-08-26
CVE-2026-32639 Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads — winter CWE-289 6.8 Medium 2026-08-26
CVE-2026-32593 Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax — winter CWE-89 5.9 Medium 2026-08-26
CVE-2026-32258 Winter: Stored XSS through Editor Settings custom styles — winter CWE-79 8.1 High 2026-08-26
CVE-2026-32257 Winter: Stored XSS through Brand Settings custom styles — winter CWE-79 8.1 High 2026-08-26
CVE-2026-35445 Winter: Authenticated backend users can bypass Users controller permission checks — winter CWE-285 7.1 High 2026-08-26
CVE-2026-79774 Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy — winter CWE-693 8.4 High 2026-08-25
CVE-2026-79773 Winter CMS before 1.2.13 Local File Inclusion via JavaScript — winter CWE-22 4.9 Medium 2026-08-25
CVE-2026-27591 Winter: Privilege escalation by authenticated backend users — winter CWE-284 10.0 Critical 2026-03-11
CVE-2026-22254 Winter Affected by Stored Cross-Site Scripting (XSS) in Asset Manager — winter CWE-79 - - 2026-02-06
CVE-2024-54149 Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion — winter CWE-184 8.5 High 2024-12-09
CVE-2024-32003 Dusk plugin may allow unfettered user authentication in misconfigured installs — wn-dusk-plugin CWE-269 8.8 High 2024-04-12
CVE-2023-52085 Winter CMS Local File Inclusion through Server Side Template Injection — winter CWE-22 3.3 Low 2023-12-29
CVE-2023-52084 Winter CMS Stored XSS through Backend ColorPicker FormWidget — winter CWE-79 2.0 Low 2023-12-28
CVE-2023-52083 Stored XSS through privileged upload of Media Manager file followed by renaming — winter CWE-79 2.0 Low 2023-12-28
CVE-2023-37269 Winter CMS vulnerable to stored XSS through privileged upload of SVG file — winter CWE-79 2.0 Low 2023-07-07
CVE-2022-39357 Winter vulnerable to Prototype Pollution in Snowboard framework — winter CWE-1321 8.1 High 2022-10-26

This page lists every published CVE security advisory associated with wintercms. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.