Wolf CMS is a lightweight, open-source content management system whose vulnerability profile centers on a single product and recurs consistently through web application input-handling issues: cross-site scripting in multiple forms, cross-site request forgery, open redirects, and improper input validation. These weakness classes are characteristic of template and form-processing logic in CMS platforms and reflect the challenges of sanitizing user-supplied content across dynamic page generation. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wolfcms over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6568HIGH Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file e | Apr 14, 2017 | 8.8 | 36 | NO | YES |
CVE-2015-6567HIGH Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "file | Apr 14, 2017 | 8.8 | 36 | NO | YES |
CVE-2018-8814MEDIUM Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settin | Apr 4, 2018 | 6.5 | 32 | NO | YES |
CVE-2012-1897MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) | Oct 1, 2012 | 6.8 | 30 | NO | YES |
CVE-2018-8813MEDIUM Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phi | Apr 4, 2018 | 4.8 | 28 | NO | YES |
CVE-2019-25070MEDIUM ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcm | Jun 9, 2022 | 6.1 | 22 | NO | NO |
CVE-2019-10646MEDIUM Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, | Mar 30, 2019 | 6.1 | 21 | NO | NO |
CVE-2012-1932MEDIUM A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to adm | Feb 19, 2020 | 4.8 | 19 | NO | NO |
CVE-2018-15842MEDIUM WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter. | Aug 25, 2018 | 4.8 | 19 | NO | NO |
CVE-2018-14837MEDIUM Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI. | Aug 10, 2018 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wolfcms.
Media articles that mention a CVE ID that affects a product developed by Wolfcms — matched by CVE ID, not by vendor name.