CVE-2020-20982: Wdja CMS

Critical severity, CVSS 9.6. EPSS: 6.2% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.

Affected products

  • Wdja Wdja CMS: version 1.5.1 only

Published 2021-11-03. Last modified 2026-06-17.