CVE-2014-8704: Wondercms

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.

Affected products

Published 2017-03-17. Last modified 2026-06-17.