wbce CVE Vulnerabilities & Metrics

Focus on wbce vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About wbce Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with wbce. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total wbce CVEs: 30
Earliest CVE date: 28 Apr 2017, 16:59 UTC
Latest CVE date: 10 Nov 2023, 06:15 UTC

Latest CVE reference: CVE-2023-39796

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical wbce CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.04

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 22
4.0-6.9 7
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS wbce CVEs

These are the five CVEs with the highest CVSS scores for wbce, sorted by severity first and recency.

All CVEs for wbce

CVE-2023-39796 wbce vulnerability CVSS: 0 10 Nov 2023, 06:15 UTC

SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter.

CVE-2023-46054 wbce vulnerability CVSS: 0 21 Oct 2023, 07:15 UTC

Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component.

CVE-2023-43871 wbce vulnerability CVSS: 0 28 Sep 2023, 14:15 UTC

A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

CVE-2023-38947 wbce vulnerability CVSS: 0 03 Aug 2023, 16:15 UTC

An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2023-29855 wbce vulnerability CVSS: 0 18 Apr 2023, 18:15 UTC

WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php.

CVE-2022-46020 wbce vulnerability CVSS: 0 20 Dec 2022, 16:15 UTC

WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.

CVE-2022-45040 wbce vulnerability CVSS: 0 25 Nov 2022, 16:15 UTC

A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field.

CVE-2022-45039 wbce vulnerability CVSS: 0 25 Nov 2022, 16:15 UTC

An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-45038 wbce vulnerability CVSS: 0 25 Nov 2022, 16:15 UTC

A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.

CVE-2022-45037 wbce vulnerability CVSS: 0 25 Nov 2022, 16:15 UTC

A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field.

CVE-2022-45036 wbce vulnerability CVSS: 0 25 Nov 2022, 16:15 UTC

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.

CVE-2022-45017 wbce vulnerability CVSS: 0 21 Nov 2022, 15:15 UTC

A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field.

CVE-2022-45016 wbce vulnerability CVSS: 0 21 Nov 2022, 15:15 UTC

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.

CVE-2022-45015 wbce vulnerability CVSS: 0 21 Nov 2022, 15:15 UTC

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field.

CVE-2022-45014 wbce vulnerability CVSS: 0 21 Nov 2022, 15:15 UTC

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field.

CVE-2022-45013 wbce vulnerability CVSS: 0 21 Nov 2022, 15:15 UTC

A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.

CVE-2022-45012 wbce vulnerability CVSS: 0 21 Nov 2022, 15:15 UTC

A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field.

CVE-2022-4006 wbce vulnerability CVSS: 0 15 Nov 2022, 22:15 UTC

A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The name of the patch is d394ba39a7bfeb31eda797b6195fd90ef74b2e75. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213716.

CVE-2022-30072 wbce vulnerability CVSS: 3.5 17 May 2022, 17:15 UTC

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.

CVE-2022-30073 wbce vulnerability CVSS: 3.5 17 May 2022, 16:15 UTC

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.

CVE-2022-28477 wbce vulnerability CVSS: 4.3 28 Apr 2022, 20:15 UTC

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-25101 wbce vulnerability CVSS: 6.8 24 Feb 2022, 15:15 UTC

A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-25099 wbce vulnerability CVSS: 6.8 24 Feb 2022, 15:15 UTC

A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2021-3817 wbce vulnerability CVSS: 7.5 09 Dec 2021, 11:15 UTC

wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

CVE-2019-17575 wbce vulnerability CVSS: 6.5 14 Oct 2019, 15:15 UTC

A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extension. (For example: place PHP code in a .jpg file, and then change the file's base name to filename.ph and change the file's extension to p. Because of concatenation, the name is then treated as filename.php.) At the result, remote attackers can execute arbitrary PHP code.

CVE-2018-6313 wbce vulnerability CVSS: 3.5 25 Jan 2018, 22:29 UTC

Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a different issue than CVE-2017-2118.

CVE-2017-1000213 wbce vulnerability CVSS: 3.5 17 Nov 2017, 01:29 UTC

WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search

CVE-2017-2120 wbce vulnerability CVSS: 6.0 28 Apr 2017, 16:59 UTC

SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

CVE-2017-2119 wbce vulnerability CVSS: 5.0 28 Apr 2017, 16:59 UTC

Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

CVE-2017-2118 wbce vulnerability CVSS: 4.3 28 Apr 2017, 16:59 UTC

Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.