Vulnerabilities (CVE)

Filtered by vendor Wondercms Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-35314 1 Wondercms 1 Wondercms 2021-06-01 7.5 HIGH 9.8 CRITICAL
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.
CVE-2020-35313 1 Wondercms 1 Wondercms 2021-04-23 7.5 HIGH 9.8 CRITICAL
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
CVE-2014-8704 1 Wondercms 1 Wondercms 2017-03-20 7.5 HIGH 9.8 CRITICAL
Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.
CVE-2014-8705 1 Wondercms 1 Wondercms 2017-03-20 7.5 HIGH 9.8 CRITICAL
PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.