Winter CMS Local File Inclusion through Server Side Template Injection
Modified: 9/10/2026
package
pkg:packagist/winter/wn-backend-module
Winter CMS Local File Inclusion through Server Side Template Injection
Modified: 9/10/2026
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata
Modified: 8/20/2026
Winter CMS Stored XSS through Backend ColorPicker FormWidget
Modified: 9/10/2026
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
Modified: 8/20/2026
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
Modified: 8/20/2026
Winter: Stored XSS through Backend List widget image columns
Modified: 8/20/2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
Modified: 8/21/2026
Winter: Reflected XSS through the search query parameter in the backend Table widget
Modified: 8/20/2026
Winter: Authenticated backend users can bypass Users controller permission checks
Modified: 8/12/2026
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
Modified: 8/12/2026
Winter: My Account preview exposes another backend user's profile by record ID
Modified: 8/20/2026
Winter: CSRF through AJAX handler names reachable as backend page actions
Modified: 8/20/2026
Winter vulnerable to privilege escalation by authenticated backend users
Modified: 3/14/2026
Winter: Stored XSS through Brand Settings custom styles
Modified: 8/12/2026
Winter: Stored XSS through Editor Settings custom styles
Modified: 8/12/2026