A stored cross-site scripting vulnerability exists in W (vincent-peugnet/wcms) through 3.18.0, allowing unauthenticated attackers to inject scripts via the login user field and visitor comment website field. This vulnerability can lead to potential script execution with administrator or editor privileges, and defenders should assess exposure and prioritize verification and remediation efforts accordingly. [truncated]
A remote code execution vulnerability exists in W (vincent-peugnet/wcms) through version 3.18.0. Authenticated editors can write arbitrary files by exploiting the unvalidated path in the POST /api/v0/media/upload/[*:path] endpoint. This allows attackers to upload .php files that can be executed by the web server. Additionally, attackers can use encoded ../ sequences to write outside the media directory an [truncated]