VulnSea

winter/wn-backend-module vulnerabilities

CVEs whose affected-version data names the winter/wn-backend-module package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

CVE-2026-54256Medium· 5.4
3w ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST parameter when resolving the attachment …

Sunlitwinter · winter/wn-backend-moduleEPSS 0.14%via NVD
CVE-2026-63179Medium· 4.9
3w ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) dire…

Sunlitwinter · winter/wn-backend-moduleEPSS 0.35%via NVD
CVE-2026-35445High
3w ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated b…

Twilightwinter · winter/wn-backend-moduleEPSS 0.25%via NVD
CVE-2026-32257High· 8.1
3w ago

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission …

Twilightwinter · winter/wn-backend-moduleEPSS 0.21%via NVD
CVE-2026-32258High· 8.1
3w ago

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are c…

Twilightwinter · winter/wn-backend-moduleEPSS 0.21%via NVD
CVE-2026-32593Medium· 5.9
3w ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configur…

Sunlitwinter · winter/wn-backend-moduleEPSS 0.17%via NVD
GHSA-7mpf-4465-7fc2Low· 2.0
1mo ago

Winter: Stored XSS through Backend List widget image columns

Winter: Stored XSS through Backend List widget image columns

Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-mpmw-f6h6-3g26Medium· 4.3
1mo ago

Winter: My Account preview exposes another backend user's profile by record ID

Winter: My Account preview exposes another backend user's profile by record ID

Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-fm29-4mq3-phg6Medium· 5.3
1mo ago

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-5cwr-5jxg-pcf6Medium· 4.5
1mo ago

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-p2ch-c2c3-4xm5Medium· 6.1
1mo ago

Winter: CSRF through AJAX handler names reachable as backend page actions

Winter: CSRF through AJAX handler names reachable as backend page actions

Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-hq84-x37p-j6q5Medium· 4.5
1mo ago

Winter: Reflected XSS through the search query parameter in the backend Table widget

Winter: Reflected XSS through the search query parameter in the backend Table widget

Sunlitwinter · winter/wn-backend-modulevia GHSA
winter/wn-backend-module vulnerabilities (CVEs) · VulnSea