Skip to main content

Vendor/product archive

wtcms_project / wtcms CVEs

Beta · best-effort

18 CVEs tagged to wtcms_project / wtcms2 Critical, 3 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2025-13786

Published Nov 30, 2025

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-13783

Published Nov 30, 2025

A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-13782

Published Nov 30, 2025

A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controll…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2024-48239

Published Oct 25, 2024

An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48238

Published Oct 25, 2024

WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48237

Published Oct 25, 2024

WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-20349

Published Sep 1, 2021

WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20348

Published Sep 1, 2021

WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20347

Published Sep 1, 2021

WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20345

Published Sep 1, 2021

WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20344

Published Sep 1, 2021

WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20343

Published Sep 1, 2021

WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8911

Published Feb 18, 2019

An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8910

Published Feb 18, 2019

An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8909

Published Feb 18, 2019

An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8908

Published Feb 18, 2019

An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" sc…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10267

Published Apr 22, 2018

WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1