CVE-2025-34506High· 8.8▾ TwilightWBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell co…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.
wbce_cms <= 1.6.3Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-58283High· 8.8WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager
CVE-2025-67504Critical· 9.1WBCE CMS is a content management system
CVE-2025-66204High· 8.1WBCE CMS is a content management system
CVE-2025-65950High· 8.8WBCE CMS is a content management system
CVE-2025-12862Medium· 6.3A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0
CVE-2025-14583High· 7.3A flaw has been found in campcodes Online Student Enrollment System 1.0