Filtered by vendor Wbce
Subscribe
Total
30 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-1000213 | 1 Wbce | 1 Wbce Cms | 2025-04-20 | 3.5 LOW | 4.8 MEDIUM |
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search | |||||
CVE-2017-2118 | 1 Wbce | 1 Wbce Cms | 2025-04-20 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2017-2120 | 1 Wbce | 1 Wbce Cms | 2025-04-20 | 6.0 MEDIUM | 7.2 HIGH |
SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2017-2119 | 1 Wbce | 1 Wbce Cms | 2025-04-20 | 5.0 MEDIUM | 8.6 HIGH |
Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors. | |||||
CVE-2022-46020 | 1 Wbce | 1 Wbce Cms | 2025-04-17 | N/A | 9.8 CRITICAL |
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. | |||||
CVE-2023-29855 | 1 Wbce | 1 Wbce Cms | 2025-02-06 | N/A | 7.2 HIGH |
WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php. | |||||
CVE-2023-46054 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component. | |||||
CVE-2023-43871 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS). | |||||
CVE-2023-39796 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 9.8 CRITICAL |
SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter. | |||||
CVE-2023-38947 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 7.2 HIGH |
An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-4006 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 3.7 LOW |
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The name of the patch is d394ba39a7bfeb31eda797b6195fd90ef74b2e75. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213716. | |||||
CVE-2022-45040 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field. | |||||
CVE-2022-45039 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 7.2 HIGH |
An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-45038 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field. | |||||
CVE-2022-45037 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field. | |||||
CVE-2022-45036 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field. | |||||
CVE-2022-45017 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 4.8 MEDIUM |
A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field. | |||||
CVE-2022-45016 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 4.8 MEDIUM |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field. | |||||
CVE-2022-45015 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 4.8 MEDIUM |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field. | |||||
CVE-2022-45014 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 4.8 MEDIUM |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field. |