VYPR

wcms

by Vincent Peugnet

CVEs (2)

  • CVE-2026-105123HigOct 4, 2026
    risk 0.57cvss 8.8epss —

    W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server,…

  • CVE-2026-105124MedOct 4, 2026
    risk 0.40cvss 6.1epss —

    W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the…