wolfcms CVE Vulnerabilities & Metrics

Focus on wolfcms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About wolfcms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with wolfcms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total wolfcms CVEs: 15
Earliest CVE date: 01 Oct 2012, 20:55 UTC
Latest CVE date: 09 Jun 2022, 17:15 UTC

Latest CVE reference: CVE-2019-25070

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical wolfcms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.41

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 7
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS wolfcms CVEs

These are the five CVEs with the highest CVSS scores for wolfcms, sorted by severity first and recency.

All CVEs for wolfcms

CVE-2019-25070 wolfcms vulnerability CVSS: 4.3 09 Jun 2022, 17:15 UTC

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcms/?/admin/user/add of the component User Add. The manipulation of the argument name leads to basic cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-135125 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2012-1932 wolfcms vulnerability CVSS: 3.5 19 Feb 2020, 15:15 UTC

A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to admin/setting.

CVE-2018-18824 wolfcms vulnerability CVSS: 3.5 25 Apr 2019, 20:29 UTC

WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.

CVE-2018-18823 wolfcms vulnerability CVSS: 3.5 25 Apr 2019, 20:29 UTC

WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.

CVE-2019-10646 wolfcms vulnerability CVSS: 4.3 30 Mar 2019, 03:29 UTC

Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded.

CVE-2018-15842 wolfcms vulnerability CVSS: 3.5 25 Aug 2018, 21:29 UTC

WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.

CVE-2018-14837 wolfcms vulnerability CVSS: 3.5 10 Aug 2018, 16:29 UTC

Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.

CVE-2018-8814 wolfcms vulnerability CVSS: 5.8 04 Apr 2018, 15:29 UTC

Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings by crafting a malicious request.

CVE-2018-8813 wolfcms vulnerability CVSS: 4.9 04 Apr 2018, 15:29 UTC

Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL.

CVE-2018-1000087 wolfcms vulnerability CVSS: 3.5 13 Mar 2018, 15:29 UTC

WolfCMS version version 0.8.3.1 contains a Reflected Cross Site Scripting vulnerability in "Create New File" and "Create New Directory" input box from 'files' Tab that can result in Session Hijacking, Spread Worms,Control the browser remotely. . This attack appear to be exploitable via Attacker can execute the JavaScript into the "Create New File" and "Create New Directory" input box from 'files'.

CVE-2018-1000084 wolfcms vulnerability CVSS: 3.5 13 Mar 2018, 15:29 UTC

WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user and compromise the admin account. This attack appear to be exploitable via Need to enter the Javascript code into Layout Name .

CVE-2018-6890 wolfcms vulnerability CVSS: 3.5 22 Feb 2018, 19:29 UTC

Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/page/edit/3.

CVE-2017-11611 wolfcms vulnerability CVSS: 3.5 08 Sep 2017, 10:29 UTC

Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks. The vulnerability exists due to insufficient sanitization of the file name in a "create-file-popup" action, and the directory name in a "create-directory-popup" action, in the HTTP POST method to the "/plugin/file_manager/" script (aka an /admin/plugin/file_manager/browse// URI).

CVE-2015-6568 wolfcms vulnerability CVSS: 6.5 14 Apr 2017, 16:59 UTC

Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for uploading a JPEG image. Exploitation requires a registered user who has access to upload functionality.

CVE-2015-6567 wolfcms vulnerability CVSS: 6.5 14 Apr 2017, 16:59 UTC

Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality.

CVE-2012-1897 wolfcms vulnerability CVSS: 6.8 01 Oct 2012, 20:55 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via the user id number to admin/user/delete; (2) delete pages via the page id number to admin/page/delete; delete the (3) images or (4) themes directory via the directory name to admin/plugin/file_manager/delete, and possibly other directories; or (5) logout the user via a request to admin/login/logout.