Known Vulnerabilities for Winston by Winstonprivacy
Listed below are 8 of the newest known vulnerabilities associated with "Winston" by "Winstonprivacy".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Winstonprivacy Winston
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-8340 json | Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permis... | Not Provided | 2026-05-22 | 2026-05-22 |
| CVE-2026-8240 json | Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured s... | Not Provided | 2026-05-21 | 2026-05-22 |
| CVE-2026-8236 json | Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dia... | Not Provided | 2026-05-21 | 2026-05-22 |
| CVE-2026-8204 json | Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cros... | Not Provided | 2026-05-21 | 2026-05-22 |
| CVE-2020-16263 json | Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by ... | 9.1 - CRITICAL | 2020-10-28 | 2020-11-03 |
| CVE-2020-16262 json | Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation. | 7.8 - HIGH | 2020-10-28 | 2021-07-21 |
| CVE-2020-16261 json | Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access. | 6.8 - MEDIUM | 2020-10-28 | 2021-07-21 |
| CVE-2020-16260 json | Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vul... | 7.5 - HIGH | 2020-10-28 | 2020-11-04 |
| CVE-2020-16259 json | Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and i... | 9.8 - CRITICAL | 2020-10-28 | 2021-07-21 |
| CVE-2020-16258 json | Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with defau... | 7.1 - HIGH | 2020-10-28 | 2020-11-04 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Winstonprivacy | Winston | - |