Vulnerabilities
Vulnerable Software
ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-10-21
ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload.
CVSS Score
6.1
EPSS Score
0.003
Published
2022-10-31
ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVSS Score
6.5
EPSS Score
0.002
Published
2022-10-31


Contact Us

Shodan ® - All rights reserved