Loading product vulnerabilities…
Total
2
Critical
0
High
1
Medium
1
CISA KEV
0
Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).
WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.