Wbce CMS
by Wbce
Source repositories
CVEs (40)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-45040 | Med | 0.35 | 5.4 | 0.00 | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field. | ||
| CVE-2022-45038 | Med | 0.35 | 5.4 | 0.01 | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field. | ||
| CVE-2022-45037 | Med | 0.35 | 5.4 | 0.01 | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field. | ||
| CVE-2022-45036 | Med | 0.35 | 5.4 | 0.00 | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field. | ||
| CVE-2022-30072 | Med | 0.35 | 5.4 | 0.01 | May 17, 2022 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters. | ||
| CVE-2022-30073 | Med | 0.35 | 5.4 | 0.02 | May 17, 2022 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. | ||
| CVE-2022-45017 | Med | 0.31 | 4.8 | 0.01 | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field. | ||
| CVE-2022-45016 | Med | 0.31 | 4.8 | 0.00 | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field. | ||
| CVE-2022-45015 | Med | 0.31 | 4.8 | 0.00 | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field. | ||
| CVE-2022-45014 | Med | 0.31 | 4.8 | 0.00 | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field. | ||
| CVE-2022-45013 | Med | 0.31 | 4.8 | 0.00 | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field. | ||
| CVE-2022-45012 | Med | 0.31 | 4.8 | 0.00 | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field. | ||
| CVE-2018-6313 | Med | 0.31 | 4.8 | 0.01 | Jan 25, 2018 | Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a different issue than CVE-2017-2118. | ||
| CVE-2017-1000213 | Med | 0.31 | 4.8 | 0.01 | Nov 17, 2017 | WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search | ||
| CVE-2021-3817 | Cri | 0.06 | 9.8 | 0.38 | Dec 9, 2021 | wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command | ||
| CVE-2025-65950 | Hig | 0.00 | 8.8 | 0.01 | Dec 10, 2025 | WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be escalated to a full database compromise, data exfiltration,… | ||
| CVE-2025-67504 | Cri | 0.00 | 9.1 | 0.01 | Dec 9, 2025 | WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account… | ||
| CVE-2025-66204 | Hig | 0.00 | 8.1 | 0.00 | Dec 9, 2025 | WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For` on each request, gaining unlimited password guessing attempts, effectively bypassing all… | ||
| CVE-2025-65094 | Hig | 0.00 | 8.8 | 0.00 | Nov 19, 2025 | WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the groups[] parameter in the /admin/users/save.php request. The UI restricts users to assigning only… | ||
| CVE-2022-4006 | Low | 0.00 | 3.7 | 0.01 | Nov 15, 2022 | A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to… |
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field.
- risk 0.35cvss 5.4epss 0.01
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.
- risk 0.35cvss 5.4epss 0.01
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.
- risk 0.35cvss 5.4epss 0.01
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.
- risk 0.35cvss 5.4epss 0.02
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.
- risk 0.31cvss 4.8epss 0.01
A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field.
- risk 0.31cvss 4.8epss 0.00
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.
- risk 0.31cvss 4.8epss 0.00
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field.
- risk 0.31cvss 4.8epss 0.00
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field.
- risk 0.31cvss 4.8epss 0.00
A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.
- risk 0.31cvss 4.8epss 0.00
A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field.
- risk 0.31cvss 4.8epss 0.01
Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a different issue than CVE-2017-2118.
- risk 0.31cvss 4.8epss 0.01
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search
- risk 0.06cvss 9.8epss 0.38
wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
- risk 0.00cvss 8.8epss 0.01
WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be escalated to a full database compromise, data exfiltration,…
- risk 0.00cvss 9.1epss 0.01
WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account…
- risk 0.00cvss 8.1epss 0.00
WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For` on each request, gaining unlimited password guessing attempts, effectively bypassing all…
- risk 0.00cvss 8.8epss 0.00
WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the groups[] parameter in the /admin/users/save.php request. The UI restricts users to assigning only…
- risk 0.00cvss 3.7epss 0.01
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to…
Page 2 of 2