WBCE CMS GitHub Repositoryproduct
https://github.com/WBCE/WBCE_CMS CVE-2022-50936
HIGH
WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)
Record summary
CVE-2022-50936 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WBCE CMSBrowse Wbce / WBCE CMS | CVE List | 1.5.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby Antonio CuomoNot analyzed1 file
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-50936 WBCE CMS Official Websiteproduct
https://wbce.org/ WBCE CMS Downloads Pageproduct
https://wbce.org/de/downloads ExploitDB-50707exploit
https://www.exploit-db.com/exploits/50707 VulnCheck Advisory: WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)Third-party advisory
https://www.vulncheck.com/advisories/wbce-cms-remote-code-execution-rce-authenticated