Known Vulnerabilities for products from Wondercms

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Wondercms".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-41425 json Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via ... Not Provided 2023-11-07 2026-07-09
CVE-2022-43332 json A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via ... 6.1 - MEDIUM 2022-11-17 2022-11-18
CVE-2021-42233 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.4 - MEDIUM 2022-05-23 2022-06-03
CVE-2020-35314 json A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows ... 9.8 - CRITICAL 2021-04-20 2021-06-01
CVE-2020-35313 json A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3... 9.8 - CRITICAL 2021-04-20 2021-04-23
CVE-2020-29469 json WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to ... 5.4 - MEDIUM 2020-12-30 2021-01-04
CVE-2020-29247 json WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page ... Not Provided 2020-12-24 2026-07-09
CVE-2020-29233 json WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an ... 5.4 - MEDIUM 2020-12-30 2021-01-04
CVE-2019-5956 json Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspec... 6.5 - MEDIUM 2019-09-12 2019-09-13
CVE-2018-1000062 json WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction()... 4.4 - MEDIUM 2018-02-09 2018-03-05
CVE-2018-14387 json An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the a... 8.8 - HIGH 2018-07-18 2018-09-19
CVE-2018-7172 json In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal. 4.9 - MEDIUM 2018-02-27 2018-03-23
CVE-2017-14523 json ** DISPUTED ** WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirec... 7.5 - HIGH 2018-01-26 2023-11-07
CVE-2017-14522 json ** DISPUTED ** In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of mali... 6.1 - MEDIUM 2018-01-26 2023-11-07
CVE-2017-14521 json In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. 8.8 - HIGH 2018-01-26 2019-04-26
CVE-2017-7951 json WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context. Not Provided 2017-04-21 2025-04-20
CVE-2014-8705 json PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PH... Not Provided 2017-03-17 2025-04-20
CVE-2014-8704 json Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary lo... Not Provided 2017-03-17 2025-04-20
CVE-2014-8703 json Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML. Not Provided 2017-03-17 2025-04-20
CVE-2014-8702 json Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the... Not Provided 2017-03-17 2025-04-20

Known software with vulnerabilities from Wondercms

Type Vendor Product Version
ApplicationWondercmsWondercms0.3.3

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report