CVE-2025-67504Critical· 9.1▾ MidnightWBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or br…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account compromise or privilege escalation if these passwords are used for new accounts or password resets. The vulnerability is fixed in version 1.6.5.
wbce_cms < 1.6.5Upgrade past the affected range:
wbce_cms 1.6.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66204High· 8.1WBCE CMS is a content management system
CVE-2025-65950High· 8.8WBCE CMS is a content management system
CVE-2025-66565Critical· 9.8Fiber Utils is a collection of common functions created for Fiber
CVE-2025-34506High· 8.8WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules
CVE-2024-58283High· 8.8WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager
CVE-2026-71851Critical· 9.0crypto-js is a JavaScript library of crypto standards