KEVIntel
9.8
CVSS
Critical

CVE-2023-39796

PUBLISHED

SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the...

Not yet in CISA KEV

Exploited in the wild PoC available Remote Low complexity No user interaction Unauthenticated
Vendor
WBCE
Product
WBCE CMS
Published
Nov 10, 2023
EPSS
6.1% · 92% pctl

Automate This Intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter.

nuclei_scanner

Weaknesses (CWE)

  • Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS Scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Status

Exploited in the wild

Recorded 2026-06-14 00:00:00 UTC · The Shadowserver (via CIRCL)

Proof of concept available

Recorded 2026-06-12 14:20:41 UTC · Nuclei Templates

Known Exploited Vulnerability Sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) First 2026-06-14 00:00 UTC

Scanner Integrations

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

CVE-2023-39796

nuclei · Created Unknown

Timeline

  • Added to KEVIntel

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • CVE Published to Public

  • CVE ID Reserved