Vulnerabilities
CVE-2025-66204 - WBCE CMS allows brute-force protection bypass using X-Forwarded-For header
CVE ID : CVE-2025-66204 Published : Dec. 8, 2025, 11:50 p.m. | 19 minutes ago Description : WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For` on each request, gaining unlimited password guessing attempts, effectively bypassing all brute-force protection. The application fully trusts the `X-Forwarded-For` header without validating it or restricting its usage. This issue is fixed in version 1.6.5. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
CVE ID
Published
Dec. 8, 2025
Source: Telegram CVE Monitor