Processwire is a focused open-source content management system whose vulnerability profile concentrates in the single core product and recurs through web-application weakness classes including cross-site request forgery, code injection, path traversal, and cross-site scripting. Vulnerabilities affecting this vendor frequently acquire public exploit tooling, reflecting the accessibility and appeal of application-layer flaws in web platforms. Defenders deploying this CMS should prioritize tracking its security updates and hardening administrative access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Processwire over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27467HIGH A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. | Feb 24, 2022 | 7.5 | 44 | NO | YES |
CVE-2022-40488MEDIUM ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF). | Oct 31, 2022 | 6.5 | 25 | NO | NO |
CVE-2022-40487MEDIUM ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attac | Oct 31, 2022 | 6.1 | 24 | NO | NO |
CVE-2025-60790MEDIUM ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling | Oct 21, 2025 | 6.5 | 23 | NO | NO |
CVE-2023-24676HIGH An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new module. NOTE: | Jan 24, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-41597MEDIUM Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intention | Jul 19, 2024 | 4.2 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Processwire.
Media articles that mention a CVE ID that affects a product developed by Processwire — matched by CVE ID, not by vendor name.