Product
wtcms project wtcms
18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-13786
CVE-2025-13783
CVE-2025-13782
CVE-2024-48239
CVE-2024-48238
CVE-2024-48237
CVE-2020-20349
CVE-2020-20348
CVE-2020-20347
CVE-2020-20345
CVE-2020-20344
CVE-2020-20343
CVE-2019-16719
CVE-2019-8911
CVE-2019-8910
CVE-2019-8909
CVE-2019-8908
CVE-2018-10267
<= 2019-12-20
A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the
<= 2019-12-20
A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function chec
<= 2019-12-20
A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the funct
all versions
An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, r
all versions
WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parame
all versions
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
all versions
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
all versions
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module
all versions
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
all versions
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers
all versions
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background artic
all versions
WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allo
all versions
WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.
all versions
An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code).
all versions
An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.
all versions
An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted d
all versions
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting - Mailbox
all versions
WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.