WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wbce
Wbce wbce Cms |
|
| Vendors & Products |
Wbce
Wbce wbce Cms |
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload. | |
| Title | WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated) | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-13T22:52:02.201Z
Updated: 2026-01-14T19:19:03.651Z
Reserved: 2026-01-11T13:34:26.329Z
Link: CVE-2022-50936
Updated: 2026-01-14T15:48:48.314Z
Status : Awaiting Analysis
Published: 2026-01-13T23:15:58.703
Modified: 2026-01-14T16:25:12.057
Link: CVE-2022-50936
No data.