Backend module for Winter CMS
89%
Total Score
100
100
94
100
Composer build tooling is present, supporting the package's build process; no security scanning tool was detected, leaving only a minor transparency gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-63179 winter/wn-backend-module is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 1.2.12. | 0.0.0 - 1.2.12 | Medium |
CVE-2026-54256 winter/wn-backend-module is vulnerable to Improper Access Control in versions 0.0.0 - 1.2.12. | 0.0.0 - 1.2.12 | Medium |
CVE-2026-35445 winter/wn-backend-module is vulnerable to Improper Authorization in versions 0.0.0 - 1.2.12. | 0.0.0 - 1.2.12 | High |
CVE-2026-32593 winter/wn-backend-module is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 1.2.12. | 0.0.0 - 1.2.12 | Medium |
CVE-2026-32258 winter/wn-backend-module is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.2.10 - 1.2.13. | 1.2.10 - 1.2.13 | High |
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^9.1 | — | — |
composer/installers Version ~1.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.