VDB
Sign up

package

Packagist/winter/wn-backend-module

pkg:packagist/winter/wn-backend-module

MEDIUM4.9Packagist
GHSA-58fp-mcx6-7qf9· CVE-2026-63179

Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets

Modified: 8/20/2026

MEDIUM4.5Packagist
GHSA-5cwr-5jxg-pcf6

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

Modified: 8/20/2026

LOW2.0Packagist
GHSA-7mpf-4465-7fc2

Winter: Stored XSS through Backend List widget image columns

Modified: 8/20/2026

HIGH8.3Packagist
GHSA-fm29-4mq3-phg6

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

Modified: 8/21/2026

MEDIUM4.5Packagist
GHSA-hq84-x37p-j6q5

Winter: Reflected XSS through the search query parameter in the backend Table widget

Modified: 8/20/2026

MEDIUM4.3Packagist
GHSA-mpmw-f6h6-3g26

Winter: My Account preview exposes another backend user's profile by record ID

Modified: 8/20/2026

MEDIUM6.1Packagist
GHSA-p2ch-c2c3-4xm5

Winter: CSRF through AJAX handler names reachable as backend page actions

Modified: 8/20/2026