Known Vulnerabilities for Winter by Wintercms
Listed below are 5 of the newest known vulnerabilities associated with "Winter" by "Wintercms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-79774 json | Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\Security... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-79773 json | Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authentic... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2023-52085 json | 5.4 - MEDIUM | 2023-12-29 | 2024-01-05 | |
| CVE-2023-52084 json | 5.4 - MEDIUM | 2023-12-28 | 2024-01-05 | |
| CVE-2023-52083 json | 4.8 - MEDIUM | 2023-12-28 | 2024-01-05 | |
| CVE-2023-37269 json | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backend.man... | 4.8 - MEDIUM | 2023-07-07 | 2024-01-25 |
| CVE-2022-39357 json | Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versio... | 9.8 - CRITICAL | 2022-10-26 | 2022-10-28 |