CVE-2020-18106: Wms Project Wms
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
Affected products
- Wms Project Wms: version 1.0 only
Published 2021-08-27. Last modified 2026-06-17.