VendorsWinterchensmy-siteall versions
Vulnerabilities

Winterchens My-site

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-53496
Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.
Published 2025-08-22 · Analyzed
9.8EPSS 0.006
CVE-2025-8838
WinterChenS my-site Backend admin preHandle improper authentication
Published 2025-08-11 · Analyzed
9.8EPSS 0.005
CVE-2025-50904
There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.
Published 2025-08-20 · Analyzed
9.8EPSS 0.004
CVE-2024-53495
Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.
Published 2025-08-20 · Analyzed
7.5EPSS 0.004
CVE-2024-57152
Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class
Published 2025-08-20 · Analyzed
7.5EPSS 0.004