VendorsWinter CMSwinterall versions
Vulnerabilities

Winter CMS Winter

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-27591
Winter: Privilege escalation by authenticated backend users
Published 2026-03-11 · Analyzed
9.9EPSS 0.006
CVE-2022-39357
Winter vulnerable to Prototype Pollution in Snowboard framework
Published 2022-10-26 · Modified
9.8EPSS 0.011
CVE-2024-54149
Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion
Published 2024-12-09 · Analyzed
8.4EPSS 0.004
CVE-2024-29686
Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes this because the payload could only be entered by a trusted user, such as the owner of the server that hosts Winter CMS, or a developer working for them.
Published 2024-03-29 · Analyzed
7.2EPSS 0.018
CVE-2023-52085
Winter CMS Local File Inclusion through Server Side Template Injection
Published 2023-12-29 · Modified
5.4EPSS 0.302
CVE-2023-52084
Winter CMS Stored XSS through Backend ColorPicker FormWidget
Published 2023-12-28 · Modified
5.4EPSS 0.003
CVE-2023-37269
Winter CMS vulnerable to stored XSS through privileged upload of SVG file
Published 2023-07-07 · Modified
4.81 PoCEPSS 0.027
CVE-2023-52083
Stored XSS through privileged upload of Media Manager file followed by renaming
Published 2023-12-28 · Modified
4.8EPSS 0.003
CVE-2026-22254
Winter Affected by Stored Cross-Site Scripting (XSS) in Asset Manager
Published 2026-02-06 · Analyzed
3.5EPSS 0.003