Wellcms is a content management system with a narrow product scope, presenting a focused vulnerability footprint centered on the core Wellcms application. The observed weakness classes—cross-site request forgery and unrestricted file uploads—reflect common input-handling and file-processing risks in web-based CMS platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wellcms over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36579HIGH Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF). | Aug 19, 2022 | 8.8 | 21 | NO | NO |
CVE-2020-21005MEDIUM WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the | Jun 3, 2021 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wellcms.
Media articles that mention a CVE ID that affects a product developed by Wellcms — matched by CVE ID, not by vendor name.