Wintercms / Winter
18 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-63179 | Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets | MEDIUM | 4.9 | Aug 26, 2026 |
| CVE-2026-54256 | Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata | MEDIUM | 5.4 | Aug 26, 2026 |
| CVE-2026-32639 | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads | MEDIUM | 6.8 | Aug 26, 2026 |
| CVE-2026-32593 | Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax | MEDIUM | 5.9 | Aug 26, 2026 |
| CVE-2026-32258 | Winter: Stored XSS through Editor Settings custom styles | HIGH | 8.1 | Aug 26, 2026 |
| CVE-2026-32257 | Winter: Stored XSS through Brand Settings custom styles | HIGH | 8.1 | Aug 26, 2026 |
| CVE-2026-35445 | Winter: Authenticated backend users can bypass Users controller permission checks | HIGH | 7.1 | Aug 26, 2026 |
| CVE-2026-79774 | Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy | CRITICAL | 9.3 | Aug 25, 2026 |
| CVE-2026-79773 | Winter CMS before 1.2.13 Local File Inclusion via JavaScript | MEDIUM | 6.9 | Aug 25, 2026 |
| CVE-2026-27591 | Winter: Privilege escalation by authenticated backend users | CRITICAL | 10.0 | Mar 11, 2026 |
| CVE-2026-22254 | Winter Affected by Stored Cross-Site Scripting (XSS) in Asset Manager | LOW | 3.5 | Feb 6, 2026 |
| CVE-2024-54149 | Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion | HIGH | 8.5 | Dec 9, 2024 |
| CVE-2024-29686 | Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS P… | HIGH | 8.7 | Mar 29, 2024 |
| CVE-2023-52085 | Winter CMS Local File Inclusion through Server Side Template Injection | MEDIUM | 5.4 | Dec 29, 2023 |
| CVE-2023-52084 | Winter CMS Stored XSS through Backend ColorPicker FormWidget | MEDIUM | 5.4 | Dec 28, 2023 |
| CVE-2023-52083 | Stored XSS through privileged upload of Media Manager file followed by renaming | MEDIUM | 4.8 | Dec 28, 2023 |
| CVE-2023-37269 | Winter CMS vulnerable to stored XSS through privileged upload of SVG file | MEDIUM | 4.8 | Jul 7, 2023 |
| CVE-2022-39357 | Winter vulnerable to Prototype Pollution in Snowboard framework | CRITICAL | 9.8 | Oct 26, 2022 |
Showing 1 to 18 of 18 CVEs