willow_cms vulnerabilities
CVEs whose affected-version data names the willow_cms package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-12331Medium· 4.7A weakness has been identified in Willow CMS up to 1.4.0
A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been ma…
▾ Sunlitmatthewdeaves · willow_cmsEPSS 0.39%via NVD
CVE-2025-12330Low· 2.4A security flaw has been discovered in Willow CMS up to 1.4.0
A security flaw has been discovered in Willow CMS up to 1.4.0. This issue affects some unknown processing of the file /admin/articles/add of the component Add Post Page. The manipulation of the argument title/body results in cross site s…
▾ Sunlitmatthewdeaves · willow_cmsEPSS 0.27%via NVD