W Cms is a web content management system with a narrow but above-typical exposure footprint. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by W Cms over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31689CRITICAL In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. I | May 22, 2023 | 9.8 | 41 | NO | NO |
CVE-2020-19902CRITICAL Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter. | Jun 27, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-8875CRITICAL A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. The manipulatio | Sep 15, 2024 | 9.1 | 28 | NO | NO |
CVE-2019-11377HIGH wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according to the fm_get_text_exts functio | Apr 20, 2019 | 8.8 | 28 | NO | NO |
CVE-2025-3800CRITICAL A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php | Apr 19, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-3799CRITICAL A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousController.php. The manipulation of th | Apr 19, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-2978CRITICAL A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=cont | Mar 31, 2025 | 9.8 | 27 | NO | NO |
CVE-2020-24136HIGH Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php. | Apr 7, 2021 | 8.6 | 27 | NO | NO |
CVE-2012-6522MEDIUM Directory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. | Jan 31, 2013 | 5.0 | 26 | NO | YES |
CVE-2020-24140HIGH Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the pagename parameter to wex/html.php. | Apr 7, 2021 | 8.3 | 25 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by W Cms.
Media articles that mention a CVE ID that affects a product developed by W Cms — matched by CVE ID, not by vendor name.