CVE-2026-54256 | Winter CMS up to 1.2.12 FileUpload form widget getFileRecord file_id access control
A vulnerability labeled as critical has been found in Winter CMS up to 1.2.12. This issue affects the function getFileRecord of the component FileUpload form widget. The manipulation of the argument file_id results in improper access controls.
This vulnerability is identified as CVE-2026-54256. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More