Wtcms Project maintains a focused content-management system whose vulnerability profile skews strongly toward critical-severity outcomes across a consistent set of input-handling and code-generation weaknesses. The recurring exposure centers on cross-site scripting, CSRF, injection, SQL injection, and code-injection flaws that reflect the application's web-facing request-processing and dynamic-code-execution surface. Defenders should prioritize patch deployment for this vendor given the severity tendency; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wtcms Project over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13782CRITICAL A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controlle | Nov 30, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-13786CRITICAL A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the a | Nov 30, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-13783CRITICAL A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/C | Nov 30, 2025 | 9.8 | 31 | NO | NO |
CVE-2018-10267HIGH WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI. | Apr 22, 2018 | 8.8 | 26 | NO | NO |
CVE-2024-48237CRITICAL WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php. | Oct 25, 2024 | 9.8 | 25 | NO | NO |
CVE-2019-8908CRITICAL An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" scr | Feb 18, 2019 | 9.8 | 24 | NO | NO |
CVE-2020-20343MEDIUM WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the ad | Sep 1, 2021 | 6.5 | 23 | NO | NO |
CVE-2020-20345MEDIUM WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered in | Sep 1, 2021 | 5.4 | 22 | NO | NO |
CVE-2019-16719MEDIUM WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS. | Sep 23, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-8910HIGH An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF. | Feb 18, 2019 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wtcms Project.
Media articles that mention a CVE ID that affects a product developed by Wtcms Project — matched by CVE ID, not by vendor name.