Skip to main content

Vendor/product archive

wintercms / winter CVEs

Beta · best-effort

9 CVEs tagged to wintercms / winter1 Critical, 3 High, 0 Medium, 4 Low, 1 Unrated.

CVE-2026-27591

Published Mar 11, 2026

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend us…

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-22254

Published Feb 6, 2026

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Man…

CVSS 0.0 · Unrated
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-54149

Published Dec 9, 2024

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access t…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29686

Published Mar 29, 2024

Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52085

Published Dec 29, 2023

Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included w…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-52084

Published Dec 28, 2023

Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would th…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-52083

Published Dec 28, 2023

Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them afte…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37269

Published Jul 7, 2023

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backend.manage_branding` permission can upload SVGs as the applic…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-39357

Published Oct 26, 2022

Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1