VYPR
Vendor

WonderCMS

Products
2
CVEs
38
Across products
38
Status
Private

Products

2

Recent CVEs

38
View all 38 CVEs →
  • CVE-2020-35313CriApr 20, 2021
    risk 0.70cvss 9.8epss 0.45

    A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.

  • CVE-2020-35314CriApr 20, 2021
    risk 0.69cvss 9.8epss 0.27

    A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.

  • CVE-2014-8705CriMar 17, 2017
    risk 0.64cvss 9.8epss 0.01

    PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.

  • CVE-2014-8704CriMar 17, 2017
    risk 0.64cvss 9.8epss 0.02

    Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.

  • CVE-2024-32340CriApr 17, 2024
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the WEBSITE TITLE parameter under the Menu module.

  • CVE-2017-14521HigJan 26, 2018
    risk 0.61cvss 8.8epss 0.07

    In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

  • CVE-2024-58305HigDec 12, 2025
    risk 0.57cvss 8.8epss 0.00

    WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by…

  • CVE-2017-7951HigApr 21, 2017
    risk 0.57cvss 8.8epss 0.01

    WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.

  • CVE-2024-27561HigMar 5, 2024
    risk 0.53cvss 8.1epss 0.01

    A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.

  • CVE-2017-14523HigJan 26, 2018
    risk 0.52cvss 7.5epss 0.08

    WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack

  • CVE-2018-14387HigJul 18, 2018
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can…

  • CVE-2014-8701HigMar 17, 2017
    risk 0.49cvss 7.5epss 0.01

    Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.

  • CVE-2023-41425MedNov 7, 2023
    risk 0.47cvss 6.1epss 0.54

    Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.

  • CVE-2025-57055MedSep 17, 2025
    risk 0.42cvss 6.5epss 0.00

    WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator can supply a malicious URL via the pluginThemeUrl POST parameter. The server fetches the provided URL using curl_exec() without…

  • CVE-2019-5956MedSep 12, 2019
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.

  • CVE-2024-32339MedApr 17, 2024
    risk 0.40cvss 6.1epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into any of the parameters.

  • CVE-2024-32337MedApr 17, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ADMIN LOGIN URL parameter under the Security module.

  • CVE-2022-43332MedNov 17, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Site title field of the Configuration Panel.

  • CVE-2017-14522MedJan 26, 2018
    risk 0.40cvss 6.1epss 0.01

    In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute JavaScript anywhere on…

  • CVE-2014-8703MedMar 17, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.