cbcvebase.

Wtcms Project Wtcms vulnerabilities

18 known vulnerabilities affecting wtcms_project/wtcms.

Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH3MEDIUM10

Vulnerabilities

Page 1 of 1
CVE-2025-13786P2CRITICALCVSS 9.8≤ 2019-12-202025-11-30
CVE-2025-13786 [CRITICAL] CWE-74 CVE-2025-13786: A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacte A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content results in code injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. This product is using a rolling rele
nvd
CVE-2025-13782P3CRITICALCVSS 9.8≤ 2019-12-202025-11-30
CVE-2025-13782 [CRITICAL] CWE-74 CVE-2025-13782: A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affec A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controller/SlideController.class.php of the component SlideController. The manipulation of the argument ids leads to sql injection. Remote exploitation of the attack is possible.
nvd
CVE-2025-13783P3CRITICALCVSS 9.8≤ 2019-12-202025-11-30
CVE-2025-13783 [CRITICAL] CWE-74 CVE-2025-13783: A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/Controller/CommentadminController.class.php of the component CommentadminController. The manipulation of the argument ids results in sql injection. The attack can be execut
nvd
CVE-2019-8908P3CRITICALCVSS 9.8v1.02019-02-18
CVE-2019-8908 [CRITICAL] CWE-706 CVE-2019-8908: An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by go An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and the "Content-Type: image/gif" header.
nvd
CVE-2024-48237P3CRITICALCVSS 9.8v1.02024-10-25
CVE-2024-48237 [CRITICAL] CWE-863 CVE-2024-48237: WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.p WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
nvd
CVE-2018-10267P3HIGHCVSS 8.8v1.02018-04-22
CVE-2018-10267 [HIGH] CWE-352 CVE-2018-10267: WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a= WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.
nvd
CVE-2019-8910P4HIGHCVSS 8.8v1.02019-02-18
CVE-2019-8910 [HIGH] CWE-352 CVE-2019-8910: An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF. An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.
nvd
CVE-2019-8909P4HIGHCVSS 7.5v1.02019-02-18
CVE-2019-8909 [HIGH] CWE-400 CVE-2019-8909: An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resou An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image.
nvd
CVE-2019-16719P4MEDIUMCVSS 6.5v1.02019-09-23
CVE-2019-16719 [MEDIUM] CWE-79 CVE-2019-16719: WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS. WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.
nvd
CVE-2024-48238P4MEDIUMCVSS 4.7v1.02024-10-25
CVE-2024-48238 [MEDIUM] CWE-89 CVE-2024-48238: WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.cla WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.
nvd
CVE-2020-20343P4MEDIUMCVSS 6.5v1.02021-09-01
CVE-2020-20343 [MEDIUM] CWE-352 CVE-2020-20343: WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav& WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background.
nvd
CVE-2019-8911P4MEDIUMCVSS 6.1v1.02019-02-18
CVE-2019-8911 [MEDIUM] CWE-79 CVE-2019-8911: An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website stat An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code).
nvd
CVE-2020-20348P4MEDIUMCVSS 5.4v1.02021-09-01
CVE-2020-20348 [MEDIUM] CWE-79 CVE-2020-20348: WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the bac WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
nvd
CVE-2020-20349P4MEDIUMCVSS 5.4v1.02021-09-01
CVE-2020-20349 [MEDIUM] CWE-79 CVE-2020-20349: WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
nvd
CVE-2020-20347P4MEDIUMCVSS 5.4v1.02021-09-01
CVE-2020-20347 [MEDIUM] CWE-79 CVE-2020-20347: WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the a WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
nvd
CVE-2020-20345P4MEDIUMCVSS 5.4v1.02021-09-01
CVE-2020-20345 [MEDIUM] CWE-79 CVE-2020-20345: WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management back WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
nvd
CVE-2020-20344P4MEDIUMCVSS 5.4v1.02021-09-01
CVE-2020-20344 [MEDIUM] CWE-79 CVE-2020-20344: WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search funct WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.
nvd
CVE-2024-48239P4MEDIUMCVSS 4.8v1.02024-10-25
CVE-2024-48239 [MEDIUM] CWE-79 CVE-2024-48239: An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).
nvd
Wtcms Project Wtcms vulnerabilities | cvebase