Threat Advisory

Winter Stored XSS through Brand Settings Custom Styles

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in winter/wn-backend-module, a package used by various applications. The overall risk and impact of these vulnerabilities are significant, as they can lead to arbitrary code execution, stored cross-site scripting (XSS), and authentication bypass. Affected version range is 1.2.13.

CVE-2026-32257 (CVSS 7.5 — High): This vulnerability allows for stored XSS through Brand Settings custom styles in the winter/wn-backend-module package. An attacker can exploit this by injecting malicious code into the settings, which will be executed when a user views the brand settings page.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in winter/wn-backend-module, a package used by various applications. The overall risk and impact of these vulnerabilities are significant, as they can lead to arbitrary code execution, stored cross-site scripting (XSS), and authentication bypass. Affected version range is 1.2.13.

CVE-2026-32257 (CVSS 7.5 — High): This vulnerability allows for stored XSS through Brand Settings custom styles in the winter/wn-backend-module package. An attacker can exploit this by injecting malicious code into the settings, which will be executed when a user views the brand settings page.[emaillocker id="1283"]

CVE-2026-32258: This vulnerability also allows for stored XSS but through Editor Settings custom styles in the same package. The attacker capability is similar to CVE-2026-32257.

CVE-2026-32593 (CVSS 8.1 — High): An SQL Injection vulnerability exists in the Backend Filter Widget numberrange Scope via numbersFromAjax functionality of the winter/wn-backend-module package. This allows an attacker with access to the backend to inject malicious SQL code, potentially leading to arbitrary code execution.

CVE-2026-35445: Authenticated backend users can bypass Users controller permission checks due to a vulnerability in the winter/wn-backend-module package. An attacker with valid credentials can exploit this by accessing restricted functionality without proper authorization.

These vulnerabilities collectively present a significant risk to applications using the affected package, particularly those that do not regularly update their dependencies. Administrators should review their exposure and apply updates as soon as possible.

RECOMMENDATION:

We recommend you to update winter/wn-backend-module to version 1.2.13.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu