Multiple security vulnerabilities have been identified in winter/wn-backend-module, a package used by various applications. The overall risk and impact of these vulnerabilities are significant, as they can lead to arbitrary code execution, stored cross-site scripting (XSS), and authentication bypass. Affected version range is 1.2.13.
CVE-2026-32257 (CVSS 7.5 — High): This vulnerability allows for stored XSS through Brand Settings custom styles in the winter/wn-backend-module package. An attacker can exploit this by injecting malicious code into the settings, which will be executed when a user views the brand settings page.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in winter/wn-backend-module, a package used by various applications. The overall risk and impact of these vulnerabilities are significant, as they can lead to arbitrary code execution, stored cross-site scripting (XSS), and authentication bypass. Affected version range is 1.2.13.
CVE-2026-32257 (CVSS 7.5 — High): This vulnerability allows for stored XSS through Brand Settings custom styles in the winter/wn-backend-module package. An attacker can exploit this by injecting malicious code into the settings, which will be executed when a user views the brand settings page.[emaillocker id="1283"]
CVE-2026-32258: This vulnerability also allows for stored XSS but through Editor Settings custom styles in the same package. The attacker capability is similar to CVE-2026-32257.
CVE-2026-32593 (CVSS 8.1 — High): An SQL Injection vulnerability exists in the Backend Filter Widget numberrange Scope via numbersFromAjax functionality of the winter/wn-backend-module package. This allows an attacker with access to the backend to inject malicious SQL code, potentially leading to arbitrary code execution.
CVE-2026-35445: Authenticated backend users can bypass Users controller permission checks due to a vulnerability in the winter/wn-backend-module package. An attacker with valid credentials can exploit this by accessing restricted functionality without proper authorization.
These vulnerabilities collectively present a significant risk to applications using the affected package, particularly those that do not regularly update their dependencies. Administrators should review their exposure and apply updates as soon as possible.
We recommend you to update winter/wn-backend-module to version 1.2.13.
The following reports contain further technical details:
[/emaillocker]