CVE-2025-34506
EUVD-2025-20293311.12.2025, 22:15
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wbce | wbce_cms | 𝑥 ≤ 1.6.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References