CVE-2026-35445 | wintercms Winter up to 1.2.12 Handler Dispatcher update_onDelete _handler permission
A vulnerability was found in wintercms Winter up to 1.2.12. It has been rated as critical. Affected by this issue is the function update_onDelete of the component Handler Dispatcher. Performing a manipulation of the argument _handler results in permission issues.
This vulnerability was named CVE-2026-35445. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More