Vincent-Peugnet Wcms vulnerabilities
2 known vulnerabilities affecting vincent-peugnet/wcms.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-105123P2HIGHCVSS 8.8≤ 3.18.02026-10-04
CVE-2026-105123 [HIGH] CWE-434 CVE-2026-105123: W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows a
W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete
nvd
CVE-2026-105124P4MEDIUMCVSS 6.1≤ 3.18.02026-10-04
CVE-2026-105124 [MEDIUM] CWE-79 CVE-2026-105124: W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that al
W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrigh
nvd