winter/wn-backend-module Security Advisories for v1.2.12 (11)
-
[MEDIUM] Winter: Reflected XSS through the search query parameter in the backend Table widget
PKSA-5ts5-4cbq-8ssk GHSA-hq84-x37p-j6q5
Affected version: >=1.0.420,<=1.2.13
Reported by:
GitHub -
[MEDIUM] Winter: CSRF through AJAX handler names reachable as backend page actions
PKSA-r35b-91gt-bn2p GHSA-p2ch-c2c3-4xm5
Affected version: >=1.0.319,<1.2.14
Reported by:
GitHub -
[MEDIUM] Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
PKSA-qr5m-g14w-86df GHSA-5cwr-5jxg-pcf6
Affected version: <=1.2.13
Reported by:
GitHub -
[HIGH] Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
PKSA-kk7w-bn2w-32z8 GHSA-fm29-4mq3-phg6
Affected version: <=1.2.13
Reported by:
GitHub -
[LOW] Winter: Stored XSS through Backend List widget image columns
PKSA-b1tx-fpj9-bp5n GHSA-7mpf-4465-7fc2
Affected version: >=1.1.0,<1.2.14
Reported by:
GitHub -
[MEDIUM] Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
PKSA-54hz-1x12-hy82 CVE-2026-63179 GHSA-58fp-mcx6-7qf9
Affected version: <=1.2.12
Reported by:
GitHub -
[MEDIUM] Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata
PKSA-dbvq-twhc-nj83 CVE-2026-54256 GHSA-3277-h8g9-qj5f
Affected version: <=1.2.12
Reported by:
GitHub -
[HIGH] Winter: Authenticated backend users can bypass Users controller permission checks
PKSA-kh9g-dm85-trgm CVE-2026-35445 GHSA-j5jq-cr68-v2xx
Affected version: <=1.2.12
Reported by:
GitHub -
[MEDIUM] Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
PKSA-rw8y-31yz-4tck CVE-2026-32593 GHSA-m7jc-g4rc-jmvh
Affected version: <=1.2.12
Reported by:
GitHub -
[HIGH] Winter: Stored XSS through Editor Settings custom styles
PKSA-g651-qxh9-xb57 CVE-2026-32258 GHSA-vgp4-2fc4-qff2
Affected version: >=1.2.10,<1.2.13
Reported by:
GitHub -
[HIGH] Winter: Stored XSS through Brand Settings custom styles
PKSA-8fbj-xdrm-f43z CVE-2026-32257 GHSA-v7cf-8gh9-gxmj
Affected version: <=1.2.12
Reported by:
GitHub