Known Vulnerabilities for products from Wcms
Listed below are 10 of the newest known vulnerabilities associated with the vendor "Wcms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-38669 json | Not Provided | 2026-05-04 | 2026-05-04 | |
| CVE-2023-31689 json | In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via... | 9.8 - CRITICAL | 2023-05-22 | 2023-05-27 |
| CVE-2020-24140 json | Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web ... | 8.3 - HIGH | 2021-04-07 | 2021-04-13 |
| CVE-2020-24139 json | Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web... | 8.3 - HIGH | 2021-04-07 | 2021-04-13 |
| CVE-2020-24138 json | Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML via th... | 6.1 - MEDIUM | 2021-04-07 | 2021-04-15 |
| CVE-2020-24137 json | Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an a... | 5.3 - MEDIUM | 2021-04-07 | 2021-04-13 |
| CVE-2020-24136 json | Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via... | 8.6 - HIGH | 2021-04-07 | 2021-04-19 |
| CVE-2020-24135 json | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inject ar... | 6.1 - MEDIUM | 2021-04-07 | 2021-04-15 |
| CVE-2020-19902 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2023-06-27 | 2023-07-06 |
| CVE-2019-14240 json | WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=.... | 8.1 - HIGH | 2019-07-23 | 2020-08-24 |
| CVE-2019-11377 json | wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a va... | 8.8 - HIGH | 2019-04-20 | 2019-04-22 |
Known software with vulnerabilities from Wcms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Wcms | Wcms | 0.0.1 |