CVE-2020-19902: Wcms

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.

Affected products

  • Wcms Wcms: version 0.3.2 only

Published 2023-06-27. Last modified 2026-06-17.