Wolf Cms
Vendor:
First CVE: Oct 1, 2012 · Active for 13 years
16
Total CVEs
More Total CVEs than 92% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wolf Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2012
13 years ago
Most Recent CVE
Jun 9, 2022
1,506 days ago
CVE Severity & Scoring
Wolf Cms16 CVEs
88%
13%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (93.8%)
Unknown1 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High0 (0.0%)
Unknown1 (6.3%)
User Interaction
None2 (12.5%)
Unknown1 (6.3%)
Required13 (81.3%)
Privileges Required
Low4 (25.0%)
High8 (50.0%)
None3 (18.8%)
Unknown1 (6.3%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6568HIGH Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file e | Apr 14, 2017 | 8.8 | 36 | NO | YES |
CVE-2015-6567HIGH Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "file | Apr 14, 2017 | 8.8 | 36 | NO | YES |
CVE-2018-8814MEDIUM Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settin | Apr 4, 2018 | 6.5 | 32 | NO | YES |
CVE-2012-1897MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) | Oct 1, 2012 | 6.8 | 30 | NO | YES |
CVE-2018-8813MEDIUM Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phi | Apr 4, 2018 | 4.8 | 28 | NO | YES |
CVE-2019-25070MEDIUM ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcm | Jun 9, 2022 | 6.1 | 22 | NO | NO |
CVE-2019-10646MEDIUM Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, | Mar 30, 2019 | 6.1 | 21 | NO | NO |
CVE-2012-1932MEDIUM A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to adm | Feb 19, 2020 | 4.8 | 19 | NO | NO |
CVE-2018-15842MEDIUM WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter. | Aug 25, 2018 | 4.8 | 19 | NO | NO |
CVE-2018-14837MEDIUM Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI. | Aug 10, 2018 | 4.8 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
31.2% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Wolf Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.8.3.1 | 11 | 5.2 | 1.3% | 0 | 2 |
| 0.7.3 | 1 | 6.8 | 1.2% | 0 | 1 |
| 0.7.2 | 1 | 6.8 | 1.2% | 0 | 1 |
| 0.7.0 | 1 | 6.8 | 1.2% | 0 | 1 |
| 0.6.0 | 1 | 6.8 | 1.2% | 0 | 1 |
| 0.5.5 | 1 | 6.8 | 1.2% | 0 | 1 |
| 0.5.0 | 1 | 6.8 | 1.2% | 0 | 1 |