winter/wn-backend-module vulnerabilities
CVEs whose affected-version data names the winter/wn-backend-module package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
12 CVEsRSS
CVE-2026-54256Medium· 5.4Winter CMS is a content management system built on the Laravel PHP framework
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST parameter when resolving the attachment …
CVE-2026-63179Medium· 4.9Winter CMS is a content management system built on the Laravel PHP framework
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) dire…
CVE-2026-35445HighWinter CMS is a content management system built on the Laravel PHP framework
Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated b…
CVE-2026-32257High· 8.1Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission …
CVE-2026-32258High· 8.1Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are c…
CVE-2026-32593Medium· 5.9Winter CMS is a content management system built on the Laravel PHP framework
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configur…
GHSA-7mpf-4465-7fc2Low· 2.0Winter: Stored XSS through Backend List widget image columns
Winter: Stored XSS through Backend List widget image columns
GHSA-mpmw-f6h6-3g26Medium· 4.3Winter: My Account preview exposes another backend user's profile by record ID
Winter: My Account preview exposes another backend user's profile by record ID
GHSA-fm29-4mq3-phg6Medium· 5.3Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
GHSA-5cwr-5jxg-pcf6Medium· 4.5Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
GHSA-p2ch-c2c3-4xm5Medium· 6.1Winter: CSRF through AJAX handler names reachable as backend page actions
Winter: CSRF through AJAX handler names reachable as backend page actions
GHSA-hq84-x37p-j6q5Medium· 4.5Winter: Reflected XSS through the search query parameter in the backend Table widget
Winter: Reflected XSS through the search query parameter in the backend Table widget