CVE-2026-32593
Last modified
CVE-2026-32593 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configured with a conditions key, allowing an authenticated backend user to inject arbitrary SQL. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configured with a conditions key, allowing an authenticated backend user to inject arbitrary SQL. The scope's filter values are interpolated into the conditions statement without parameter binding, so a user with access to a list view whose filter uses this scope and configuration can supply crafted input through the filter's AJAX handler and read arbitrary database contents. No built-in Winter CMS backend views use this scope type and configuration combination, so exploitation requires a third-party plugin to have registered a numberrange filter scope with a conditions key, and a vanilla installation without such plugins is not affected. This issue is fixed in version 1.2.13.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| wintercms | winter | < 1.2.13 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-32593?
How severe is CVE-2026-32593?
How do I fix CVE-2026-32593?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-32587Missing Authorization vulnerability in Saad Iqbal WP EasyPay…5.4
- CVE-2026-32588Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0…6.5
- CVE-2026-32589A flaw was found in Red Hat Quay's container image upload pr…7.4
- CVE-2026-3259A Generation of Error Message Containing Sensitive Informati…7.1
- CVE-2026-32590A flaw was found in Red Hat Quay's handling of resumable con…8.8
- CVE-2026-32591A flaw was found in Red Hat Quay's Proxy Cache configuration…5.5
- CVE-2026-32594Parse Server is an open source backend that can be deployed …7.3
- CVE-2026-32595Traefik is an HTTP reverse proxy and load balancer. Versions…3.7
- CVE-2026-32596Glances is an open-source system cross-platform monitoring t…7.5
- CVE-2026-32597PyJWT is a JSON Web Token implementation in Python. Prior to…7.5
- CVE-2026-32598OneUptime is a solution for monitoring and managing online s…6.5
- CVE-2026-32599Netmaker makes networks with WireGuard. Prior to version 1.5…5.3
Are you affected by CVE-2026-32593?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
