CVE-2025-34506

Source
https://cve.org/CVERecord?id=CVE-2025-34506
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-34506.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-34506
Published
2025-12-11T21:44:03.538Z
Modified
2026-08-12T03:51:41.250197049Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
WBCE CMS 1.6.3 Authenticated Remote Code Execution via Module Upload
Details

WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.

Database specific
{
    "cwe_ids": [
        "CWE-434"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/34xxx/CVE-2025-34506.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/wbce/wbce_cms

Affected ranges

Type
GIT
Repo
https://github.com/wbce/wbce_cms
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:wbce:wbce_cms:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.6.3"
        },
        {
            "last_affected": "1.6.3"
        },
        {
            "introduced": "0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

1.*
1.6.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-34506.json"