CVE-2018-14958: Weaselcms Project Weaselcms
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php.
Affected products
- Weaselcms Project Weaselcms: version 0.3.5 only
Published 2018-08-05. Last modified 2026-06-17.