Filtered by vendor Wbce
Subscriptions
Filtered by product Wbce Cms
Subscriptions
Total
30 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-45017 | 1 Wbce | 1 Wbce Cms | 2024-08-03 | 4.8 Medium |
A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field. | ||||
CVE-2022-30073 | 1 Wbce | 1 Wbce Cms | 2024-08-03 | 5.4 Medium |
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. | ||||
CVE-2022-30072 | 1 Wbce | 1 Wbce Cms | 2024-08-03 | 5.4 Medium |
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters. | ||||
CVE-2022-28477 | 1 Wbce | 1 Wbce Cms | 2024-08-03 | 6.1 Medium |
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). | ||||
CVE-2022-25101 | 1 Wbce | 1 Wbce Cms | 2024-08-03 | 7.8 High |
A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. | ||||
CVE-2022-25099 | 1 Wbce | 1 Wbce Cms | 2024-08-03 | 7.8 High |
A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. | ||||
CVE-2022-4006 | 1 Wbce | 1 Wbce Cms | 2024-08-03 | 3.7 Low |
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The name of the patch is d394ba39a7bfeb31eda797b6195fd90ef74b2e75. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213716. | ||||
CVE-2023-43871 | 1 Wbce | 1 Wbce Cms | 2024-08-02 | 5.4 Medium |
A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS). | ||||
CVE-2023-38947 | 1 Wbce | 1 Wbce Cms | 2024-08-02 | 7.2 High |
An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file. | ||||
CVE-2023-29855 | 1 Wbce | 1 Wbce Cms | 2024-08-02 | 7.2 High |
WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php. |