WBCE is a content management system platform that, despite a narrow product portfolio, maintains a more prominent presence in the vulnerability landscape than its focused scope might suggest. Vulnerabilities affecting the vendor skew toward moderate severity and frequently acquire public exploit code, reflecting the web-application attack surface inherent to CMS platforms. The exposure recurs through application-layer weakness classes including cross-site scripting, unsafe file uploads, SQL injection, and brute-force authentication flaws, which are characteristic of server-side web frameworks handling user input and file handling. Defenders should treat WBCE instances as requiring regular patch cycles and input-validation hardening, particularly where the CMS is internet-exposed; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wbce over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3817CRITICAL wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command | Dec 9, 2021 | 9.8 | 65 | NO | YES |
CVE-2022-46020CRITICAL WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. | Dec 20, 2022 | 9.8 | 64 | NO | YES |
CVE-2023-39796CRITICAL SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter. | Nov 10, 2023 | 9.8 | 41 | NO | YES |
CVE-2025-67504CRITICAL WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secu | Dec 9, 2025 | 9.8 | 34 | NO | NO |
CVE-2022-50936HIGH WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attac | Jan 13, 2026 | 8.8 | 31 | NO | NO |
CVE-2022-45038MEDIUM A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected i | Nov 25, 2022 | 5.4 | 29 | NO | YES |
CVE-2025-34506HIGH WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a special | Dec 11, 2025 | 8.8 | 28 | NO | NO |
CVE-2024-58283HIGH WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers | Dec 10, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-65094HIGH WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the gro | Nov 19, 2025 | 8.8 | 28 | NO | NO |
CVE-2022-30073MEDIUM WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. | May 17, 2022 | 5.4 | 28 | NO | YES |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wbce.
Media articles that mention a CVE ID that affects a product developed by Wbce — matched by CVE ID, not by vendor name.