Логотип exploitDog
bind:CVE-2026-22254
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22254

Количество 2

Количество 2

nvd логотип

CVE-2026-22254

2 дня назад

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to upload SVGs without automatic sanitization. To actively exploit this security issue, an attacker would need access to the Backend with a user account with the following permission: cms.manage_assets. The Winter CMS maintainers strongly recommend that the cms.manage_assets permission only be reserved to trusted administrators and developers in general. This vulnerability is fixed in 1.2.10.

EPSS: Низкий
github логотип

GHSA-m7gw-rffq-rxjm

4 дня назад

Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22254

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to upload SVGs without automatic sanitization. To actively exploit this security issue, an attacker would need access to the Backend with a user account with the following permission: cms.manage_assets. The Winter CMS maintainers strongly recommend that the cms.manage_assets permission only be reserved to trusted administrators and developers in general. This vulnerability is fixed in 1.2.10.

0%
Низкий
2 дня назад
github логотип
GHSA-m7gw-rffq-rxjm

Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager

0%
Низкий
4 дня назад

Уязвимостей на страницу