Wolf Cms

Vendor:

First CVE: Oct 1, 2012 · Active for 13 years

16
Total CVEs
More Total CVEs than 92% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Wolf Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2012
13 years ago
Most Recent CVE
Jun 9, 2022
1,506 days ago

CVE Severity & Scoring

Wolf Cms16 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (93.8%)
Unknown1 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High0 (0.0%)
Unknown1 (6.3%)
User Interaction
None2 (12.5%)
Unknown1 (6.3%)
Required13 (81.3%)
Privileges Required
Low4 (25.0%)
High8 (50.0%)
None3 (18.8%)
Unknown1 (6.3%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file e
Apr 14, 20178.836NOYES
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "file
Apr 14, 20178.836NOYES
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settin
Apr 4, 20186.532NOYES
Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1)
Oct 1, 20126.830NOYES
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phi
Apr 4, 20184.828NOYES
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcm
Jun 9, 20226.122NONO
Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input,
Mar 30, 20196.121NONO
A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to adm
Feb 19, 20204.819NONO
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
Aug 25, 20184.819NONO
Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.
Aug 10, 20184.819NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
31.2% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Wolf Cms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.8.3.1115.21.3%02
0.7.316.81.2%01
0.7.216.81.2%01
0.7.016.81.2%01
0.6.016.81.2%01
0.5.516.81.2%01
0.5.016.81.2%01