CVE-2020-24136: Wcms

High severity, CVSS 8.6. EPSS: 2.2% chance of exploitation in the next 30 days.

Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php.

Affected products

  • Wcms Wcms: version 0.3.2 only

Published 2021-04-07. Last modified 2026-06-17.