WBCE Vulnerabilities and Affected Products
Vulnerabilities associated with WBCE CMS.
Products
Clear product- WBCE_CMS6 vulnerabilities
- WBCE CMS3 vulnerabilities
- CMS1 vulnerability
- wbce/wbce_cms1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-50936HIGH | WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload. CWE-434Jan 13, 2026 | CVSS8.7v4.0 | EPSS0.816% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34506HIGH | WBCE CMS 1.6.3 Authenticated Remote Code Execution via Module UploadWBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed. CWE-434Dec 11, 2025 | CVSS8.6v4.0 | EPSS0.888% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-58283HIGH | WBCE CMS 1.6.2 Remote Code Execution via Elfinder File UploadWBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter. CWE-434Dec 10, 2025 | CVSS8.7v4.0 | EPSS0.65% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |