CVE-2014-8705: Wondercms

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.

Affected products

Published 2017-03-17. Last modified 2026-06-17.