CVE-2018-14958: Weaselcms Project Weaselcms

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php.

Affected products

Published 2018-08-05. Last modified 2026-06-17.