CVE-2020-21005: Wellcms

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.

Affected products

Published 2021-06-03. Last modified 2026-06-17.