Winter CMS is a modestly represented content management system platform whose vulnerabilities skew toward serious outcomes with an elevated tendency toward public exploit availability. The recurring exposure centers on the core Winter product through web-facing weakness classes including cross-site scripting variants, authorization bypass, improper access control, and path traversal—reflecting the authentication and input-handling demands of a user-editable CMS. Defenders should prioritize patches for this vendor given the confluence of critical severity and public exploit code; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wintercms over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-52085MEDIUM Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included wi | Dec 29, 2023 | 5.4 | 41 | NO | YES |
CVE-2026-27591CRITICAL Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend use | Mar 11, 2026 | 9.9 | 32 | NO | NO |
CVE-2022-39357CRITICAL Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype p | Oct 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-37269MEDIUM Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backend.manage_branding` permission can upload SVGs as the applica | Jul 7, 2023 | 4.8 | 25 | NO | YES |
CVE-2024-54149HIGH Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access to | Dec 9, 2024 | 8.4 | 23 | NO | NO |
CVE-2024-29686HIGH Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin | Mar 29, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-52084MEDIUM Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would the | Dec 28, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-52083MEDIUM Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after | Dec 28, 2023 | 4.8 | 17 | NO | NO |
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Mana | Feb 6, 2026 | 3.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wintercms.
Media articles that mention a CVE ID that affects a product developed by Wintercms — matched by CVE ID, not by vendor name.