CVE-2020-18106: Wms Project Wms

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.

Affected products

Published 2021-08-27. Last modified 2026-06-17.