Home/Product/wondercms
Product

wondercms

36 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-57055
all versions
WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authentica
6.5MEDIUM
CVE-2025-3123
all versions
A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function insta
4.7MEDIUM
CVE-2024-41305
all versions
A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arb
4.7MEDIUM
CVE-2024-41304
all versions
An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrar
5.4MEDIUM
CVE-2024-32746
all versions
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web s
4.6MEDIUM
CVE-2024-32745
all versions
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web s
5.9MEDIUM
CVE-2024-32744
all versions
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web s
4.6MEDIUM
CVE-2024-32743
all versions
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web s
5.5MEDIUM
CVE-2024-32341
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the Home page of WonderCMS v3.4.3 allows attackers to execute arbitrary web
5.4MEDIUM
CVE-2024-32340
all versions
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web s
9.6CRITICAL
CVE-2024-32339
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary w
6.1MEDIUM
CVE-2024-32338
all versions
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web s
5.4MEDIUM
CVE-2024-32337
all versions
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web s
6.1MEDIUM
CVE-2024-27563
all versions
A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application
5.3MEDIUM
CVE-2024-27561
all versions
A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force
8.1HIGH
CVE-2023-41425
>= 3.2.0 and <= 3.4.2
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a cra
6.1MEDIUM
CVE-2022-43332
all versions
A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a cra
6.1MEDIUM
CVE-2020-35314
all versions
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remot
9.8CRITICAL
CVE-2020-35313
all versions
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3
9.8CRITICAL
CVE-2020-29469
all versions
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to injec
5.4MEDIUM
CVE-2020-29233
all versions
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attac
5.4MEDIUM
CVE-2020-29247
all versions
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywo
4.8MEDIUM
CVE-2019-5956
<= 2.6.0
Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified
6.5MEDIUM
CVE-2018-14387
< 2.5.2
An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associ
8.8HIGH
CVE-2018-7172
<= 2.4.0
In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal.
4.9MEDIUM
CVE-2018-1000062
all versions
WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'sv
4.4MEDIUM
CVE-2017-14523
all versions
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the ve
7.5HIGH
CVE-2017-14522
all versions
In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOT
6.1MEDIUM
CVE-2017-14521
all versions
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
8.8HIGH
CVE-2017-7951
<= 2.0.2
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.
8.8HIGH
CVE-2014-8705
all versions
PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP cod
9.8CRITICAL
CVE-2014-8704
all versions
Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local f
9.8CRITICAL
CVE-2014-8703
all versions
Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.
6.1MEDIUM
CVE-2014-8702
all versions
Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the pass
5.3MEDIUM
CVE-2014-8701
all versions
Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5
7.5HIGH
CVE-2011-5317
<= 0.3.3
Cross-site scripting (XSS) vulnerability in editText.php in WonderCMS before 0.4 allows remote attackers to inject arbitrary web s
threatengine.sh