Known Vulnerabilities for products from Wondercms
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Wondercms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-41425 json | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via ... | Not Provided | 2023-11-07 | 2026-07-09 |
| CVE-2022-43332 json | A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via ... | 6.1 - MEDIUM | 2022-11-17 | 2022-11-18 |
| CVE-2021-42233 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.4 - MEDIUM | 2022-05-23 | 2022-06-03 |
| CVE-2020-35314 json | A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows ... | 9.8 - CRITICAL | 2021-04-20 | 2021-06-01 |
| CVE-2020-35313 json | A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3... | 9.8 - CRITICAL | 2021-04-20 | 2021-04-23 |
| CVE-2020-29469 json | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to ... | 5.4 - MEDIUM | 2020-12-30 | 2021-01-04 |
| CVE-2020-29247 json | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page ... | Not Provided | 2020-12-24 | 2026-07-09 |
| CVE-2020-29233 json | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an ... | 5.4 - MEDIUM | 2020-12-30 | 2021-01-04 |
| CVE-2019-5956 json | Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspec... | 6.5 - MEDIUM | 2019-09-12 | 2019-09-13 |
| CVE-2018-1000062 json | WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction()... | 4.4 - MEDIUM | 2018-02-09 | 2018-03-05 |
| CVE-2018-14387 json | An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the a... | 8.8 - HIGH | 2018-07-18 | 2018-09-19 |
| CVE-2018-7172 json | In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal. | 4.9 - MEDIUM | 2018-02-27 | 2018-03-23 |
| CVE-2017-14523 json | ** DISPUTED ** WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirec... | 7.5 - HIGH | 2018-01-26 | 2023-11-07 |
| CVE-2017-14522 json | ** DISPUTED ** In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of mali... | 6.1 - MEDIUM | 2018-01-26 | 2023-11-07 |
| CVE-2017-14521 json | In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. | 8.8 - HIGH | 2018-01-26 | 2019-04-26 |
| CVE-2017-7951 json | WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context. | Not Provided | 2017-04-21 | 2025-04-20 |
| CVE-2014-8705 json | PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PH... | Not Provided | 2017-03-17 | 2025-04-20 |
| CVE-2014-8704 json | Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary lo... | Not Provided | 2017-03-17 | 2025-04-20 |
| CVE-2014-8703 json | Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML. | Not Provided | 2017-03-17 | 2025-04-20 |
| CVE-2014-8702 json | Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the... | Not Provided | 2017-03-17 | 2025-04-20 |
Known software with vulnerabilities from Wondercms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Wondercms | Wondercms | 0.3.3 |