Webcms develops a web content management portal product that, despite a narrow footprint, represents a typical attack surface for application-layer systems. Its disclosed vulnerabilities cluster around input-handling weaknesses, specifically SQL injection and cross-site scripting flaws, which are endemic to web application frameworks and require careful input validation and output encoding. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webcms over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4186HIGH SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. NOTE: the provenance of this | Sep 23, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4185HIGH SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different | Sep 23, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3213HIGH SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter to portal/index.p | Jul 18, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4184MEDIUM Cross-site scripting (XSS) vulnerability in index.php in webCMS Portal Edition allows remote attackers to inject arbitrary web script or HTML via the patron parameter. NOTE: the p | Sep 23, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webcms.
Media articles that mention a CVE ID that affects a product developed by Webcms — matched by CVE ID, not by vendor name.