W3bcms is a content management system with a narrow product footprint that includes its core CMS offering and associated modules such as a guestbook component. The recurring vulnerability signal centers on SQL injection and related input-handling flaws affecting the CMS and its extensions, reflecting common risks in web-application database integration. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by W3bcms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6158HIGH Multiple unspecified vulnerabilities in the admin backend in w3b>cms (aka w3blabor CMS) before 3.2.0 have unknown impact and remote attack vectors. | Feb 17, 2009 | 10.0 | 35 | NO | YES |
CVE-2009-2337MEDIUM SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execut | Jul 7, 2009 | 6.8 | 27 | NO | YES |
CVE-2009-0597MEDIUM SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL comma | Feb 16, 2009 | 6.8 | 27 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by W3bcms.
Media articles that mention a CVE ID that affects a product developed by W3bcms — matched by CVE ID, not by vendor name.