Free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. Originally known as October CMS.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2024-29686 wintercms/winter is vulnerable to Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in versions 0.0.0 - 1.2.3. | 0.0.0 - 1.2.3 | High |
CVE-2023-37269 wintercms/winter is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.2.3. | 0.0.0 - 1.2.3 | Low |
CVE-2022-39357 wintercms/winter is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 1.1.8 - 1.1.10 and 1.2.0 - 1.2.1. | 1.1.8 - 1.1.101.2.0 - 1.2.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
winter/storm Version ~1.2.0 | — | — |
laravel/framework Version ^9.1 | — | — |
winter/wn-cms-module Version ~1.2.0 | — | — |
winter/wn-system-module Version ~1.2.0 | — | — |
winter/wn-backend-module Version ~1.2.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant