Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

W Cms

First CVE: Apr 20, 2019Active for: 7 yearsTotal CVEs: 19

W Cms is a web content management system with a narrow but above-typical exposure footprint. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 56% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by W Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2013
13 years ago
Most Recent CVE
May 25, 2025
425 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-31689CRITICAL
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. I
May 22, 20239.841NONO
CVE-2020-19902CRITICAL
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.
Jun 27, 20239.831NONO
CVE-2024-8875CRITICAL
A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. The manipulatio
Sep 15, 20249.128NONO
CVE-2019-11377HIGH
wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according to the fm_get_text_exts functio
Apr 20, 20198.828NONO
CVE-2025-3800CRITICAL
A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php
Apr 19, 20259.827NONO
CVE-2025-3799CRITICAL
A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousController.php. The manipulation of th
Apr 19, 20259.827NONO
CVE-2025-2978CRITICAL
A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=cont
Mar 31, 20259.827NONO
CVE-2020-24136HIGH
Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php.
Apr 7, 20218.627NONO
CVE-2012-6522MEDIUM
Directory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter.
Jan 31, 20135.026NOYES
CVE-2020-24140HIGH
Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the pagename parameter to wex/html.php.
Apr 7, 20218.325NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
32%
37%
32%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (89.5%)
Unknown2 (10.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (84.2%)
High1 (5.3%)
Unknown2 (10.5%)
User Interaction
None13 (68.4%)
Unknown2 (10.5%)
Required4 (21.1%)
Privileges Required
Low2 (10.5%)
High1 (5.3%)
None14 (73.7%)
Unknown2 (10.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
10.5% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by W Cms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by W Cms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For W Cms's Products

View all 2 CNAs →

Top CWEs