Wondercms

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 38
    Known Exploited: 0
    5
    Critical Level Threats
    8
    High Level Threats
    25
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-58305

    WonderCMS 4.3.2 Cross-Site Scripting Remote Code Execution via Module Installation

    Last Modified: Apr 15, 2026
    Published: Dec 12, 2025

    CVE-2025-57055

    WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator can supply a malicious URL via the pluginThemeUrl POST parameter. The server fetches the provided URL using curl_exec() without sufficient validation, allowing the attacker to force internal or external HTTP requests.

    Last Modified: Sep 23, 2025
    Published: Sep 17, 2025

    CVE-2025-3123

    WonderCMS Theme Installation/Plugin Installation installUpdateModuleAction unrestricted upload

    Last Modified: May 28, 2025
    Published: Apr 02, 2025

    CVE-2024-41304

    An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafted SVG file.

    Last Modified: Apr 11, 2025
    Published: Jul 30, 2024

    CVE-2024-41305

    A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.

    Last Modified: Nov 21, 2024
    Published: Jul 30, 2024
    Items Per Page
    Wondercms Vulnerabilities & Security CVEs | CVE-DB