winter/wn-system-module
Packagist3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting winter/wn-system-modulepage 1 of 1
- CVE-2023-52083MEDIUMCVSS 4.8EG 4.8✓ Fixed in 1.2.42023-12-28
vulnerable: v1.0.473 ... v1.2.3 (15 versions)
Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanit…
- CVE-2026-79773MEDIUMCVSS 4.9EG 4.9✓ Fixed in 1.2.132026-08-25
vulnerable: v1.0.473 ... v1.2.9 (26 versions)
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =r…
- CVE-2026-79774HIGHCVSS 8.4EG 8.4✓ Fixed in 1.2.132026-08-25
vulnerable: v1.2.10 ... v1.2.9 (6 versions)
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. A…
Check whether winter/wn-system-module is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for winter/wn-system-module CVEs against the assets you own.
Start Free Scan →