Vulnerabilities
Vulnerable Software
Wbce:  >> Wbce Cms  >> 1.5.4  Security Vulnerabilities
Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-10-21
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
CVSS Score
9.8
EPSS Score
0.846
Published
2022-12-20
An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file.
CVSS Score
7.2
EPSS Score
0.001
Published
2022-11-25
A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-11-25
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-11-25
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field.
CVSS Score
5.4
EPSS Score
0.132
Published
2022-11-25
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.
CVSS Score
5.4
EPSS Score
0.132
Published
2022-11-25
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field.
CVSS Score
4.8
EPSS Score
0.001
Published
2022-11-21
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field.
CVSS Score
4.8
EPSS Score
0.001
Published
2022-11-21
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.
CVSS Score
4.8
EPSS Score
0.001
Published
2022-11-21


Contact Us

Shodan ® - All rights reserved