Known Vulnerabilities for products from Wtcms Project
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Wtcms Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-13786 json | A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch o... | Not Provided | 2025-11-30 | 2026-04-29 |
| CVE-2025-13783 json | A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function... | Not Provided | 2025-11-30 | 2026-04-29 |
| CVE-2025-13782 json | A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the ... | Not Provided | 2025-11-30 | 2026-04-29 |
| CVE-2020-20349 json | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links mod... | 5.4 - MEDIUM | 2021-09-01 | 2021-09-07 |
| CVE-2020-20348 json | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management m... | 5.4 - MEDIUM | 2021-09-01 | 2021-09-07 |
| CVE-2020-20347 json | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module. | 5.4 - MEDIUM | 2021-09-01 | 2021-09-07 |
| CVE-2020-20345 json | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attac... | Not Provided | 2021-09-01 | 2026-07-09 |
| CVE-2020-20344 json | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background ... | 5.4 - MEDIUM | 2021-09-01 | 2021-09-07 |
| CVE-2020-20343 json | WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that... | 6.5 - MEDIUM | 2021-09-01 | 2021-09-07 |
| CVE-2019-16719 json | WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS. | 6.5 - MEDIUM | 2019-09-23 | 2020-08-24 |
| CVE-2019-8911 json | An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code). | 6.1 - MEDIUM | 2019-02-18 | 2019-02-19 |
| CVE-2019-8910 json | An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF. | 8.8 - HIGH | 2019-02-18 | 2019-02-19 |
| CVE-2019-8909 json | An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via craf... | 7.5 - HIGH | 2019-02-18 | 2019-02-19 |
| CVE-2019-8908 json | An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Ma... | 9.8 - CRITICAL | 2019-02-18 | 2021-07-21 |
| CVE-2018-10267 json | WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI. | 8.8 - HIGH | 2018-04-22 | 2018-05-25 |
Known software with vulnerabilities from Wtcms Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Wtcms Project | Wtcms | 1.0 |