Wn backend module: Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax (CVE-2026-32593)
Winter CMS backend Filter widget is vulnerable to SQL injection via the numberrange scope when configured with a conditions key. An authenticated backend user with access to a list view containing such a filter scope can exploit this to inject arbitrary SQL through the filter's AJAX handler. This could allow read access to the full database contents. The vulnerability requires a third-party plugin to register the vulnerable filter scope; no default Winter CMS backend views are affected. The issue is fixed in Winter CMS version 1.2.13.
AI Analysis
Technical Summary
The Backend Filter widget (Backend\Widgets\Filter) in Winter CMS is vulnerable to SQL injection through the numberrange scope type when the scope is configured with a conditions key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler. Exploitation requires a third-party plugin to register a numberrange filter scope with the conditions configuration key, as no built-in backend views use this combination. The vulnerability allows potential read access to the full database contents. The issue is addressed in Winter CMS v1.2.13, and a manual patch commit is available for users unable to upgrade.
Potential Impact
An authenticated backend user with appropriate access can exploit this vulnerability to perform SQL injection via the filter's AJAX handler, potentially gaining unauthorized read access to the entire database. This could lead to exposure of sensitive data stored in the database. However, exploitation requires a third-party plugin registering a vulnerable filter scope; default installations without such plugins are not affected.
Mitigation Recommendations
A patch is available in Winter CMS version 1.2.13 that fixes this SQL injection vulnerability. Users are strongly advised to upgrade to this version. If upgrading is not immediately possible, users may apply the manual patch available at commit 50713de95adf5298536d93f4d999652525d36d43 in the Winter CMS repository to mitigate the issue.
Wn backend module: Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax (CVE-2026-32593)
Description
Winter CMS backend Filter widget is vulnerable to SQL injection via the numberrange scope when configured with a conditions key. An authenticated backend user with access to a list view containing such a filter scope can exploit this to inject arbitrary SQL through the filter's AJAX handler. This could allow read access to the full database contents. The vulnerability requires a third-party plugin to register the vulnerable filter scope; no default Winter CMS backend views are affected. The issue is fixed in Winter CMS version 1.2.13.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Backend Filter widget (Backend\Widgets\Filter) in Winter CMS is vulnerable to SQL injection through the numberrange scope type when the scope is configured with a conditions key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler. Exploitation requires a third-party plugin to register a numberrange filter scope with the conditions configuration key, as no built-in backend views use this combination. The vulnerability allows potential read access to the full database contents. The issue is addressed in Winter CMS v1.2.13, and a manual patch commit is available for users unable to upgrade.
Potential Impact
An authenticated backend user with appropriate access can exploit this vulnerability to perform SQL injection via the filter's AJAX handler, potentially gaining unauthorized read access to the entire database. This could lead to exposure of sensitive data stored in the database. However, exploitation requires a third-party plugin registering a vulnerable filter scope; default installations without such plugins are not affected.
Mitigation Recommendations
A patch is available in Winter CMS version 1.2.13 that fixes this SQL injection vulnerability. Users are strongly advised to upgrade to this version. If upgrading is not immediately possible, users may apply the manual patch available at commit 50713de95adf5298536d93f4d999652525d36d43 in the Winter CMS repository to mitigate the issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-m7jc-g4rc-jmvh
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-32593"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7c9b39bf8831d539cdc762
Added to database: 08/12/2026, 16:11:37 UTC
Last enriched: 08/12/2026, 16:32:06 UTC
Last updated: 08/12/2026, 16:32:06 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.