CVE-2025-66204
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
09/12/2025
Last modified:
11/12/2025
Description
WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For` on each request, gaining unlimited password guessing attempts, effectively bypassing all brute-force protection. The application fully trusts the `X-Forwarded-For` header without validating it or restricting its usage. This issue is fixed in version 1.6.5.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wbce:wbce_cms:*:*:*:*:*:*:*:* | 1.6.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



