CVE-2026-32639 | WinterCMS Winter up to 1.2.12 Theme Editor AJAX handlers/AssetList widget onSave/onDelete/onDeleteTemplates/onUpload privileges management
A vulnerability identified as problematic has been detected in WinterCMS Winter up to 1.2.12. This vulnerability affects the function onSave/onDelete/onDeleteTemplates/onUpload of the component Theme Editor AJAX handlers/AssetList widget. The manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-32639. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More