Showing 7 vulnerabilities on this page for winter/wn-backend-module

Signals CISA KEV Ransomware Nuclei
Packagist vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Winter: Authenticated backend users can bypass Users controller permission checks

### Impact Affected versions of Winter CMS did not validate the handler name submitted through the form postback mechanism (`_handler` POST field) in the same way as AJAX requests (`X_WINTER_REQUEST_HANDLER` header). The AJAX path validates that handler names match the `on[A-Z][\w+]*` pattern, but the postback path passed the handler name directly to the handler dispatcher with no validation. This allowed an authenticated backend user to call any method on a controller — including action-prefi

CWE-285CWE-639Aug 12, 2026
CVSS-v4.0EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax

## Impact The Backend Filter widget (`Backend\Widgets\Filter`) is vulnerable to SQL injection through the `numberrange` scope type when the scope is configured with a `conditions` key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler, potentially gaining read access to the full database contents. To exploit this, an attacker must have a valid backend account with access to a list view where a th

CWE-89Aug 12, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Winter: Stored XSS through Editor Settings custom styles

### Impact Authenticated Backend Users with the `backend.manage_editor` ("Manage editor settings") permission can provide custom styles through **Settings → Editor Settings → Markup Styles** that are compiled through the LESS CSS parser and rendered on every backend page. Previous

CWE-79Aug 12, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Winter: Stored XSS through Brand Settings custom styles

### Impact Users with the `backend.manage_branding` ("Customize the back-end") permission can provide custom CSS through **Settings → Customize Backend → Styles** that is compiled through the LESS CSS parser and rendered on every backend page. Previously, the compiled output was not sanitized, which could have allowed a stored XSS attack. Although this is a valid security issue, it's importan

CWE-79Aug 12, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Winter: Privilege escalation by authenticated backend users

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifying the roles / permissions assigned to their account through specially crafted requests to the backend while logged in. To actively exploit this security issue, an attacker would need access to the Backend with a user account with any level of access

CVSS10.0v3.1EPSS0.486%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Winter CMS Local File Inclusion through Server Side Template Injection

Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via LESS. This had the potential to lead to a Local File Inclusion vulnerability. This issue has been patched in v1.2.4.

CWE-22Dec 29, 20231 related artifact
CVSS3.3v3.1EPSS30.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Winter CMS Stored XSS through Backend ColorPicker FormWidget

Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be rendered unescaped in the backend form, potentially allowing for a stored XSS attack. This issue has been patched in v1.2.4.

CWE-79Dec 28, 2023
CVSS2.0v3.1EPSS0.309%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX