winter/wn-backend-module vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-HQ84-X37P-J6Q5Mediumwinter/wn-backend-module: Winter: Reflected XSS through the search query parameter in the backend Table widgetGHSA-P2CH-C2C3-4XM5Mediumwinter/wn-backend-module: Winter: CSRF through AJAX handler names reachable as backend page actionsGHSA-5CWR-5JXG-PCF6Mediumwinter/wn-backend-module: Winter: Stored XSS through cached Brand Settings and Editor Settings custom stylesGHSA-FM29-4MQ3-PHG6Highwinter/wn-backend-module: Winter: ImportExportController AJAX handlers bypass granular import/export permission gateGHSA-MPMW-F6H6-3G26Mediumwinter/wn-backend-module: Winter: My Account preview exposes another backend user's profile by record IDGHSA-7MPF-4465-7FC2Lowwinter/wn-backend-module: Winter: Stored XSS through Backend List widget image columnsCVE-2026-63179Mediumwinter/wn-backend-module: Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assetsCVE-2026-54256Mediumwinter/wn-backend-module: Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadataCVE-2026-35445Highwinter/wn-backend-module: Winter: Authenticated backend users can bypass Users controller permission checksCVE-2026-32593Mediumwinter/wn-backend-module: Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjaxCVE-2026-32258Highwinter/wn-backend-module: Winter: Stored XSS through Editor Settings custom stylesCVE-2026-32257Highwinter/wn-backend-module: Winter: Stored XSS through Brand Settings custom stylesCVE-2026-27591Criticalwinter/wn-backend-module: Winter vulnerable to privilege escalation by authenticated backend usersCVE-2023-52085Lowwinter/wn-backend-module: Winter CMS Local File Inclusion through Server Side Template Injection CVE-2023-52084Lowwinter/wn-backend-module: Winter CMS Stored XSS through Backend ColorPicker FormWidget

Stop the waste.
Protect your environment with Kodem.