VYPR

WellCMS

by WellCMS

CVEs (2)

  • CVE-2022-36579HigAug 19, 2022
    risk 0.57cvss 8.8epss 0.00

    Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).

  • CVE-2020-21005MedJun 3, 2021
    risk 0.42cvss 6.5epss 0.01

    WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.