VendorsWBCEwbce_cmsany version
Vulnerabilities

WBCE CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2021-3817
SQL Injection in wbce/wbce_cms
Published 2021-12-09 · Modified
9.81 PoCEPSS 0.384
CVE-2025-67504
WBCE CMS has Weak Random Number Generator in Password Generation Function
Published 2025-12-09 · Analyzed
9.8EPSS 0.005
CVE-2025-65950
WBCE CMS is Vulnerable to Time-Based Blind SQL Injection through groups[] Parameter
Published 2025-12-10 · Analyzed
9.4EPSS 0.005
CVE-2025-34506
WBCE CMS 1.6.3 Authenticated Remote Code Execution via Module Upload
Published 2025-12-11 · Analyzed
8.8EPSS 0.009
CVE-2025-65094
WBCE CMS is Vulnerable to Privilege Escalation via Group ID Manipulation (IDOR)
Published 2025-11-19 · Analyzed
8.8EPSS 0.004
CVE-2017-2119
Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
Published 2017-04-28 · Modified
8.6EPSS 0.035
CVE-2025-66204
WBCE CMS allows brute-force protection bypass using X-Forwarded-For header
Published 2025-12-08 · Analyzed
8.1EPSS 0.005
CVE-2022-4006
WBCE CMS Header class.login.php increase_attempts excessive authentication
Published 2022-11-15 · Modified
7.5EPSS 0.008
CVE-2019-17575
A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extension. (For example: place PHP code in a .jpg file, and then change the file's base name to filename.ph and change the file's extension to p. Because of concatenation, the name is then treated as filename.php.) At the result, remote attackers can execute arbitrary PHP code.
Published 2019-10-14 · Modified
7.2EPSS 0.014
CVE-2017-2120
SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
Published 2017-04-28 · Modified
7.2EPSS 0.013
CVE-2017-2118
Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-04-28 · Modified
6.1EPSS 0.012
CVE-2023-46054
Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component.
Published 2023-10-21 · Modified
5.4EPSS 0.004
CVE-2022-45017
A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field.
Published 2022-11-21 · Modified
4.8EPSS 0.006
CVE-2022-45013
A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.
Published 2022-11-21 · Modified
4.8EPSS 0.005
CVE-2022-45014
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field.
Published 2022-11-21 · Modified
4.8EPSS 0.005
CVE-2022-45015
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field.
Published 2022-11-21 · Modified
4.8EPSS 0.005
CVE-2022-45016
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.
Published 2022-11-21 · Modified
4.8EPSS 0.005
CVE-2022-45012
A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field.
Published 2022-11-21 · Modified
4.8EPSS 0.005