Wcms is a modestly represented web content management system whose vulnerability profile skews strongly toward critical-severity outcomes across a focused product line. The recurring exposure centers on input and access-control weaknesses characteristic of web applications—path traversal, unrestricted file uploads, cross-site scripting, improper access control, and injection flaws—that reflect the challenges of secure data handling in user-facing CMS platforms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wcms over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31689CRITICAL In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. I | May 22, 2023 | 9.8 | 41 | NO | NO |
CVE-2020-19902CRITICAL Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter. | Jun 27, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-8875CRITICAL A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. The manipulatio | Sep 15, 2024 | 9.1 | 28 | NO | NO |
CVE-2019-11377HIGH wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according to the fm_get_text_exts functio | Apr 20, 2019 | 8.8 | 28 | NO | NO |
CVE-2025-3800CRITICAL A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php | Apr 19, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-3799CRITICAL A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousController.php. The manipulation of th | Apr 19, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-2978CRITICAL A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=cont | Mar 31, 2025 | 9.8 | 27 | NO | NO |
CVE-2020-24136HIGH Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php. | Apr 7, 2021 | 8.6 | 27 | NO | NO |
CVE-2012-6522MEDIUM Directory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. | Jan 31, 2013 | 5.0 | 26 | NO | YES |
CVE-2020-24140HIGH Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable web application via the pagename parameter to wex/html.php. | Apr 7, 2021 | 8.3 | 25 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wcms.
Media articles that mention a CVE ID that affects a product developed by Wcms — matched by CVE ID, not by vendor name.