CVE-2025-34506
HIGHWbce Cms < 1.6.3 - Unrestricted File Upload
Title source: ruleDescription
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.
Exploits (1)
References (6)
Scores
CVSS v3
8.8
EPSS
0.0101
EPSS Percentile
77.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (2)
WBCE/WBCE CMS
1.6.3
wbce/wbce_cms
< 1.6.3
Published
Dec 11, 2025
Tracked Since
Feb 18, 2026