Vendorswtcms Projectwtcmsall versions
Vulnerabilities

wtcms Project wtcms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2019-8908
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and the "Content-Type: image/gif" header.
Published 2019-02-18 · Modified
9.8EPSS 0.023
CVE-2025-13786
taosir WTCMS index.php fetch code injection
Published 2025-11-30 · Analyzed
9.8EPSS 0.006
CVE-2024-48237
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
Published 2024-10-25 · Analyzed
9.8EPSS 0.005
CVE-2025-13782
taosir WTCMS SlideController SlideController.class.php delete sql injection
Published 2025-11-30 · Analyzed
9.8EPSS 0.004
CVE-2025-13783
taosir WTCMS CommentadminController CommentadminController.class.php delete sql injection
Published 2025-11-30 · Analyzed
9.8EPSS 0.003
CVE-2019-8910
An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.
Published 2019-02-18 · Modified
8.8EPSS 0.006
CVE-2018-10267
WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.
Published 2018-04-21 · Modified
8.8EPSS 0.005
CVE-2019-8909
An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image.
Published 2019-02-18 · Modified
7.5EPSS 0.018
CVE-2019-16719
WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.
Published 2019-09-23 · Modified
6.5EPSS 0.005
CVE-2020-20343
WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background.
Published 2021-09-01 · Modified
6.5EPSS 0.004
CVE-2019-8911
An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code).
Published 2019-02-18 · Modified
6.1EPSS 0.008
CVE-2020-20345
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
Published 2021-09-01 · Modified
5.4EPSS 0.005
CVE-2020-20348
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
Published 2021-09-01 · Modified
5.4EPSS 0.005
CVE-2020-20349
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
Published 2021-09-01 · Modified
5.4EPSS 0.005
CVE-2020-20344
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.
Published 2021-09-01 · Modified
5.4EPSS 0.005
CVE-2020-20347
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
Published 2021-09-01 · Modified
5.4EPSS 0.005
CVE-2024-48239
An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).
Published 2024-10-25 · Analyzed
4.8EPSS 0.002
CVE-2024-48238
WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.
Published 2024-10-25 · Analyzed
4.7EPSS 0.003