{"id":"CVE-2026-32593","aliases":["GHSA-m7jc-g4rc-jmvh"],"url":"https://o3.security/vulnerability/CVE-2026-32593","summary":"Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax","details":"## Impact\n\nThe Backend Filter widget (`Backend\\Widgets\\Filter`) is vulnerable to SQL injection through the `numberrange` scope type when the scope is configured with a `conditions` key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler, potentially gaining read access to the full database contents.\n\nTo exploit this, an attacker must have a valid backend account with access to a list view where a third-party plugin has registered a `numberrange` filter scope using the `conditions` configuration key. No built-in Winter CMS backend views use this scope type and configuration combination, so a vanilla installation without plugins is not exploitable.\n\n## Patches\n\nThis issue has been fixed in Winter CMS v1.2.13.\n\n## Workarounds\n\nIf users cannot upgrade, they may apply commit https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43 to your Winter CMS\ninstallation manually to resolve this issue.","published":"2026-08-26T17:27:07.836Z","modified":"2026-09-11T03:31:04.035974820Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"},"epss":{"score":0.00171,"percentile":0.06858,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"winter/wn-backend-module","fixedVersion":"1.2.13"}],"fix":{"url":"https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43","label":"wintercms/winter@50713de"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32593.json"},{"type":"ADVISORY","url":"https://github.com/wintercms/winter/security/advisories/GHSA-m7jc-g4rc-jmvh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32593"},{"type":"FIX","url":"https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43"},{"type":"PACKAGE","url":"https://github.com/wintercms/winter"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T03:31:04.035974820Z"}}