NONE🇵🇱 Wersja polska

CVE-2026-22254

CVSS 0.0v3.1pub. 2026-02-06upd. 2026-02-20

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to upload SVGs without automatic sanitization. To actively exploit this security issue, an attacker would need access to the Backend with a user account with the following permission: cms.manage_assets. The Winter CMS maintainers strongly recommend that the cms.manage_assets permission only be reserved to trusted administrators and developers in general. This vulnerability is fixed in 1.2.10.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:N
  • Wintercms Winter

    APP
    Wintercms
    < 1.2.10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-27591CRITICAL9.9PL ✓same product

Winter CMS – privilege escalation przez modyfikację ról i uprawnień

CVE-2024-54149HIGH8.4same product

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS p...

CVE-2024-29686HIGH7.2same product

Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute ...

CVE-2022-39357HIGH8.1same product

Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard fram...

CVE-2023-52085LOW3.3same product

Winter to darmowy, open-source'owy system zarządzania treścią. Użytkownicy mający dostęp do formularzy backend...