CVE-2025-65950High· 8.8▾ MidnightPoC availableWBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be escalated to a ful…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
1 GitHub repo (last check)
WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be escalated to a full database compromise, data exfiltration, effectively bypassing all security controls. The vulnerability exists in the admin/users/save.php script, which handles updates to user profiles. The script improperly processes the groups[] parameter sent from the user edit form. This issue is fixed in version 1.6.5.
wbce_cms < 1.6.5Upgrade past the affected range:
wbce_cms 1.6.5Connected by shared product, vendor, weakness, or advisory.
CVE-2017-18362Critical· 9.8ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database
CVE-2019-7481High· 7.5Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources
CVE-2025-10601High· 7.3A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0
CVE-2025-10602Medium· 6.3A vulnerability was found in SourceCodester Online Exam Form Submission 1.0
CVE-2025-10598High· 7.3A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0
CVE-2025-10599High· 7.3A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0