Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wolfcms

First CVE: Oct 1, 2012Active for: 14 yearsTotal CVEs: 16
36.7
VTI Score
Medium

Wolf CMS is a lightweight, open-source content management system whose vulnerability profile centers on a single product and recurs consistently through web application input-handling issues: cross-site scripting in multiple forms, cross-site request forgery, open redirects, and improper input validation. These weakness classes are characteristic of template and form-processing logic in CMS platforms and reflect the challenges of sanitizing user-supplied content across dynamic page generation. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wolfcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2012
13 years ago
Most Recent CVE
Jun 9, 2022
1,509 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-6568HIGH
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file e
Apr 14, 20178.836NOYES
CVE-2015-6567HIGH
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "file
Apr 14, 20178.836NOYES
CVE-2018-8814MEDIUM
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settin
Apr 4, 20186.532NOYES
CVE-2012-1897MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1)
Oct 1, 20126.830NOYES
CVE-2018-8813MEDIUM
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phi
Apr 4, 20184.828NOYES
CVE-2019-25070MEDIUM
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcm
Jun 9, 20226.122NONO
CVE-2019-10646MEDIUM
Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input,
Mar 30, 20196.121NONO
CVE-2012-1932MEDIUM
A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to adm
Feb 19, 20204.819NONO
CVE-2018-15842MEDIUM
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
Aug 25, 20184.819NONO
CVE-2018-14837MEDIUM
Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.
Aug 10, 20184.819NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
88%
13%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (93.8%)
Unknown1 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High0 (0.0%)
Unknown1 (6.3%)
User Interaction
None2 (12.5%)
Unknown1 (6.3%)
Required13 (81.3%)
Privileges Required
Low4 (25.0%)
High8 (50.0%)
None3 (18.8%)
Unknown1 (6.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
31.2% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wolfcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wolfcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wolfcms's Products

View all 2 CNAs →

Top CWEs