Feed/CVE-2026-32593
CVE-2026-32593MEDIUMCVSS 5.9

Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax

Published Aug 12, 2026·Updated Aug 12, 2026

NVD Description

## Impact The Backend Filter widget (`Backend\Widgets\Filter`) is vulnerable to SQL injection through the `numberrange` scope type when the scope is configured with a `conditions` key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler, potentially gaining read access to the full database contents. To exploit this, an attacker must have a valid backend account with access to a list view where a third-party plugin has registered a `numberrange` filter scope using the `conditions` configuration key. No built-in Winter CMS backend views use this scope type and configuration combination, so a vanilla installation without plugins is not exploitable. ## Patches This issue has been fixed in Winter CMS v1.2.13. ## Workarounds If users cannot upgrade, they may apply commit https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43 to your Winter CMS installation manually to resolve this issue.

Affected Packages (1)

winter/wn-backend-moduleCOMPOSER
Fixed in = 1.2.12

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free