CVE-2023-36339: Webboss Webboss.io CMS

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET request.

Affected products

  • Webboss Webboss.io CMS: before 3.7.0.1 (fixed in 3.7.0.1)

Published 2023-07-21. Last modified 2026-06-17.