WebsitebakerCVEs & Vulnerabilities

16 CVEs affecting Websitebaker products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

websitebaker 16
CVE-2021-47788HIGH

WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server.

16 Jan 2026
8.8
CVSS
CVE-2023-53953MEDIUM

WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating web pages. Attackers can craft malicious payloads in page titles that execute arbitrary JavaScript when the page is viewed by other users.

20 Dec 2025
5.4
CVSS
CVE-2023-53903MEDIUM

WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.

16 Dec 2025
5.4
CVSS
CVE-2023-53902MEDIUM

WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.

16 Dec 2025
6.5
CVSS
CVE-2020-25990CRITICAL

WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

1 Oct 2020
9.8
CVSS
CVE-2011-4322HIGH

websitebaker prior to and including 2.8.1 has an authentication error in backup module.

21 Jan 2020
7.5
CVSS
CVE-2011-2934HIGH

A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.

15 Jan 2020
8.8
CVSS
CVE-2011-2933HIGH

An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.

15 Jan 2020
7.2
CVSS
CVE-2017-16514MEDIUM

Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert persistent JavaScript code that gets reflected back to users in multiple areas in the application.

10 Jan 2018
6.1
CVSS
CVE-2017-9771CRITICAL

install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or database_password parameter.

21 Jun 2017
9.8
CVSS
CVE-2017-9361MEDIUM

WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.

2 Jun 2017
6.1
CVSS
CVE-2017-9360CRITICAL

WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.

2 Jun 2017
9.8
CVSS
CVE-2017-7410CRITICAL

Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) display_name parameter.

4 Apr 2017
9.8
CVSS
CVE-2015-0553MEDIUM

Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.

21 Jan 2015
4.3
CVSS
CVE-2014-9243MEDIUMpoc

Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to wb/admin/admintools/tool.php or (2) section_id parameter to edit_module_files.php, (3) news/add_post.php, (4) news/modify_group.php, (5) news/modify_post.php, or (6) news/modify_settings.php in wb/modules/.

3 Dec 2014
4.3
CVSS
CVE-2014-9242HIGHpoc

SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

3 Dec 2014
7.5
CVSS
← PrevPage 1 / 1Next →