CVE-2020-24138: Wcms

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML via the pagename parameter to wex/html.php.

Affected products

  • Wcms Wcms: version 0.3.2 only

Published 2021-04-07. Last modified 2026-06-17.