winter has 15 CVEs on record. Disclosure cadence is accelerating: 15 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 15. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (5) and CWE-639 (3). Most affected products: winter/wn-backend-module (12), winter/wn-system-module (2), winter/wn-cms-module (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 15 prev 0
Products
- winter/wn-backend-module 12
- winter/wn-system-module 2
- winter/wn-cms-module 1
Worst active — by depth score
GHSA-8cfw-pcwh-v63wHigh· 8.4Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)46CVE-2026-32258High· 8.1Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework45CVE-2026-32257High· 8.1Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework45CVE-2026-35445HighWinter CMS is a content management system built on the Laravel PHP framework41CVE-2026-32639Medium· 6.8Winter CMS is a content management system built on the Laravel PHP framework37
winter vulnerabilities
CVEs affecting winter, newest first. Open any entry for full detail, references, and exploit status.
15 CVEsRSS
CVE-2026-54256Medium· 5.4Winter CMS is a content management system built on the Laravel PHP framework
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST parameter when resolving the attachment …
CVE-2026-63179Medium· 4.9Winter CMS is a content management system built on the Laravel PHP framework
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) dire…
CVE-2026-32639Medium· 6.8Winter CMS is a content management system built on the Laravel PHP framework
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend us…
CVE-2026-35445HighWinter CMS is a content management system built on the Laravel PHP framework
Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated b…
CVE-2026-32257High· 8.1Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission …
CVE-2026-32258High· 8.1Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are c…
CVE-2026-32593Medium· 5.9Winter CMS is a content management system built on the Laravel PHP framework
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configur…
GHSA-2223-f22x-24cqMedium· 4.9Winter: Local File Inclusion through =include directives in JavaScript asset compilation
Winter: Local File Inclusion through =include directives in JavaScript asset compilation
GHSA-8cfw-pcwh-v63wHigh· 8.4Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)
Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)
GHSA-7mpf-4465-7fc2Low· 2.0Winter: Stored XSS through Backend List widget image columns
Winter: Stored XSS through Backend List widget image columns
GHSA-mpmw-f6h6-3g26Medium· 4.3Winter: My Account preview exposes another backend user's profile by record ID
Winter: My Account preview exposes another backend user's profile by record ID
GHSA-fm29-4mq3-phg6Medium· 5.3Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
GHSA-5cwr-5jxg-pcf6Medium· 4.5Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
GHSA-p2ch-c2c3-4xm5Medium· 6.1Winter: CSRF through AJAX handler names reachable as backend page actions
Winter: CSRF through AJAX handler names reachable as backend page actions
GHSA-hq84-x37p-j6q5Medium· 4.5Winter: Reflected XSS through the search query parameter in the backend Table widget
Winter: Reflected XSS through the search query parameter in the backend Table widget