CVE-2020-21005: Wellcms
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.
Affected products
- Wellcms Wellcms: version 2.0 only
Published 2021-06-03. Last modified 2026-06-17.