VYPR

Wondercms

by WonderCMS

Source repositories

CVEs (8)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2014-8705Cri0.649.80.01Mar 17, 2017PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.
CVE-2014-8704Cri0.649.80.01Mar 17, 2017Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.
CVE-2024-58305Hig0.578.80.00Dec 12, 2025WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticated administrator into accessing a malicious link.
CVE-2017-7951Hig0.578.80.00Apr 21, 2017WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.
CVE-2014-8701Hig0.497.50.00Mar 17, 2017Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.
CVE-2014-8703Med0.406.10.00Mar 17, 2017Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.
CVE-2014-8702Med0.345.30.00Mar 17, 2017Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals the installation path in an error message.
CVE-2011-53170.000.00Jan 1, 2015Cross-site scripting (XSS) vulnerability in editText.php in WonderCMS before 0.4 allows remote attackers to inject arbitrary web script or HTML via the content parameter.