Showing 3 vulnerabilities on this page for WBCE CMS

Signals CISA KEV Ransomware Nuclei
WBCE vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)

WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload.

CWE-434Jan 13, 2026
CVSS8.7v4.0EPSS0.816%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

WBCE CMS 1.6.3 Authenticated Remote Code Execution via Module Upload

WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.

CWE-434Dec 11, 2025
CVSS8.6v4.0EPSS0.888%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

WBCE CMS 1.6.2 Remote Code Execution via Elfinder File Upload

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system commands through a user-controlled parameter.

CWE-434Dec 10, 2025
CVSS8.7v4.0EPSS0.65%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX