Skip to main content

Vendor/product archive

wolfcms / wolf_cms CVEs

Beta · best-effort

16 CVEs tagged to wolfcms / wolf_cms0 Critical, 2 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2019-25070

Published Jun 9, 2022

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfc…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1932

Published Feb 19, 2020

A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to ad…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18824

Published Apr 25, 2019

WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18823

Published Apr 25, 2019

WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10646

Published Mar 30, 2019

Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14837

Published Aug 10, 2018

Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8814

Published Apr 4, 2018

Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/setti…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8813

Published Apr 4, 2018

Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct ph…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000087

Published Mar 13, 2018

WolfCMS version version 0.8.3.1 contains a Reflected Cross Site Scripting vulnerability in "Create New File" and "Create New Directory" input box from 'files' Tab that can result…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000084

Published Mar 13, 2018

WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6890

Published Feb 22, 2018

Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/page/edit/3.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11611

Published Sep 8, 2017

Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks. The vulnerability exists due to insufficient sanitization of the file name in a "create-file-popup" action, and the dir…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6568

Published Apr 14, 2017

Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6567

Published Apr 14, 2017

Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "fil…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1897

Published Oct 1, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1