MEDIUM6.8Packagist
GHSA-5c4f-9pq9-6c77· CVE-2026-32639Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
Modified: 8/12/2026
package
pkg:packagist/winter/wn-cms-module
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
Modified: 8/12/2026
Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager
Modified: 2/6/2026
Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion
Modified: 9/10/2026