wondercms CVE Vulnerabilities & Metrics

Focus on wondercms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About wondercms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with wondercms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total wondercms CVEs: 24
Earliest CVE date: 01 Jan 2015, 11:59 UTC
Latest CVE date: 30 Jul 2024, 18:15 UTC

Latest CVE reference: CVE-2024-41305

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -66.67%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -66.67%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical wondercms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.37

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 10
7.0-8.9 5
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS wondercms CVEs

These are the five CVEs with the highest CVSS scores for wondercms, sorted by severity first and recency.

All CVEs for wondercms

CVE-2024-41305 wondercms vulnerability CVSS: 0 30 Jul 2024, 18:15 UTC

A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.

CVE-2024-27563 wondercms vulnerability CVSS: 0 05 Mar 2024, 17:15 UTC

A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.

CVE-2024-27561 wondercms vulnerability CVSS: 0 05 Mar 2024, 17:15 UTC

A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.

CVE-2023-41425 wondercms vulnerability CVSS: 0 07 Nov 2023, 16:15 UTC

Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.

CVE-2022-43332 wondercms vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Site title field of the Configuration Panel.

CVE-2020-35314 wondercms vulnerability CVSS: 7.5 20 Apr 2021, 20:15 UTC

A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.

CVE-2020-35313 wondercms vulnerability CVSS: 7.5 20 Apr 2021, 20:15 UTC

A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.

CVE-2020-29469 wondercms vulnerability CVSS: 3.5 30 Dec 2020, 15:15 UTC

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload in the Setting - Menu and each time any user will visits the website directory, the XSS triggers and attacker can steal the cookie according to the crafted payload.

CVE-2020-29233 wondercms vulnerability CVSS: 3.5 30 Dec 2020, 15:15 UTC

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and attacker can steal the cookie according to the crafted payload.

CVE-2020-29247 wondercms vulnerability CVSS: 3.5 24 Dec 2020, 20:15 UTC

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, and the attacker can able to steal the cookie according to the crafted payload.

CVE-2019-5956 wondercms vulnerability CVSS: 7.5 12 Sep 2019, 17:15 UTC

Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.

CVE-2018-14387 wondercms vulnerability CVSS: 6.8 18 Jul 2018, 19:29 UTC

An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can access the user's account through the active session. The Session Fixation attack fixes a session on the victim's browser, so the attack starts before the user logs in.

CVE-2018-7172 wondercms vulnerability CVSS: 5.5 27 Feb 2018, 15:29 UTC

In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal.

CVE-2018-1000062 wondercms vulnerability CVSS: 3.5 09 Feb 2018, 23:29 UTC

WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This attack appear to be exploitable via Crafted SVG File.

CVE-2017-14523 wondercms vulnerability CVSS: 5.0 26 Jan 2018, 20:29 UTC

WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack

CVE-2017-14522 wondercms vulnerability CVSS: 4.3 26 Jan 2018, 20:29 UTC

In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute JavaScript anywhere on their website

CVE-2017-14521 wondercms vulnerability CVSS: 6.5 26 Jan 2018, 20:29 UTC

In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

CVE-2017-7951 wondercms vulnerability CVSS: 6.8 21 Apr 2017, 02:59 UTC

WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.

CVE-2014-8705 wondercms vulnerability CVSS: 7.5 17 Mar 2017, 14:59 UTC

PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.

CVE-2014-8704 wondercms vulnerability CVSS: 7.5 17 Mar 2017, 14:59 UTC

Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.

CVE-2014-8703 wondercms vulnerability CVSS: 4.3 17 Mar 2017, 14:59 UTC

Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.

CVE-2014-8702 wondercms vulnerability CVSS: 5.0 17 Mar 2017, 14:59 UTC

Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals the installation path in an error message.

CVE-2014-8701 wondercms vulnerability CVSS: 5.0 17 Mar 2017, 14:59 UTC

Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.

CVE-2011-5317 wondercms vulnerability CVSS: 4.3 01 Jan 2015, 11:59 UTC

Cross-site scripting (XSS) vulnerability in editText.php in WonderCMS before 0.4 allows remote attackers to inject arbitrary web script or HTML via the content parameter.