Winterchens maintains a narrowly scoped web application portfolio centered on its My Site product, where the durable vulnerability signal centers on authentication and access-control issues including authentication bypass and improper access-control weaknesses. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winterchens over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8838CRITICAL A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHandle of the file /admin/ of the c | Aug 11, 2025 | 9.8 | 34 | NO | NO |
CVE-2024-53496CRITICAL Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication. | Aug 22, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-50904CRITICAL There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without an | Aug 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-57152HIGH Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInte | Aug 20, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-53495HIGH Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication. | Aug 20, 2025 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winterchens.
Media articles that mention a CVE ID that affects a product developed by Winterchens — matched by CVE ID, not by vendor name.