Security: wintercms/winter
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Stored XSS through Backend List widget image columnsGHSA-7mpf-4465-7fc2 published
Aug 19, 2026 by LukeTowersLow -
My Account preview exposes another backend user's profile by record IDGHSA-mpmw-f6h6-3g26 published
Aug 19, 2026 by LukeTowersModerate -
ImportExportController AJAX handlers bypass granular import/export permission gateGHSA-fm29-4mq3-phg6 published
Aug 19, 2026 by LukeTowersHigh -
Stored XSS through cached Brand Settings and Editor Settings custom stylesGHSA-5cwr-5jxg-pcf6 published
Aug 19, 2026 by LukeTowersModerate -
CSRF through AJAX handler names reachable as backend page actionsGHSA-p2ch-c2c3-4xm5 published
Aug 19, 2026 by LukeTowersModerate -
Reflected XSS through the search query parameter in the backend Table widgetGHSA-hq84-x37p-j6q5 published
Aug 19, 2026 by LukeTowersModerate -
Local File Inclusion through =include directives in JavaScript asset compilationGHSA-2223-f22x-24cq published
Aug 7, 2026 by LukeTowersModerate -
Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assetsGHSA-58fp-mcx6-7qf9 published
Aug 7, 2026 by LukeTowersModerate -
Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadataGHSA-3277-h8g9-qj5f published
Aug 7, 2026 by LukeTowersModerate -
Authenticated backend users can bypass Users controller permission checksGHSA-j5jq-cr68-v2xx published
Aug 7, 2026 by LukeTowersHigh