W3 Total Cache <= 2.8.12 - Unauthenticated Command Injection
W3 Total Cache
Minimum safe version
2.9.4
Update to 2.9.4 or later to address 49 fixable vulnerabilities
W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header
CVE-2026-27384
CVE-2024-12365
CVE-2024-12006
CVE-2024-12008
CVE-2023-5359
W3 Total Cache <= 0.9.4 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting
W3 Total Cache <= 0.9.4.1 - Cross-Site Scripting via request_id
W3 Total Cache <= 0.9.4.1 - Arbitrary Code Execution via settings import
W3 Total Cache <= 0.9.4.1 - Authenticated Arbitrary File Download
W3 Total Cache <= 0.9.4.1 - Arbitrary File Upload
W3 Total Cache <= 0.9.4.1 - Security Token Bypass via Type Juggling
W3 Total Cache <= 0.9.4 - Server-Side Request Forgery leading to Host Information Disclosure
W3 Total Cache <= 0.9.4.1 - Weak validation of Amazon SNS push messages
W3 Total Cache plugin <= 0.9.7.3 - Reflected Cross-Site Scripting
W3 Total Cache <= 0.9.7.3 - Improper Input Validation via openssl_verify
W3 Total Cache <= 0.9.7.3 - Server Side Request Forgery
W3 Total Cache <= 0.9.2.4 - Sensitive Information Exposure
W3 Total Cache <= 0.9.2.4 - Password Hash Extraction
CVE-2022-31090
W3 Total Cache <= 0.9.2.4 - Insecure Cryptography to Sensitive Information Disclosure
W3 Total Cache 0.9.4 - Edge Mode Enabling CSRF
W3 Total Cache <= 0.9.4.1 - Authenticated Reflected Cross-Site Scripting (XSS)
W3 Total Cache <= 0.9.4.1 – Unauthenticated Security Token Bypass
W3 Total Cache <= 0.9.4.1 – Authenticated Arbitrary PHP Code Execution
W3 Total Cache <= 0.9.4.1 – Authenticated Arbitrary File Upload
W3 Total Cache <= 0.9.4.1 – Authenticated Arbitrary File Download
W3 Total Cache <= 0.9.4 - Unauthenticated Server Side Request Forgery (SSRF)
W3 Total Cache <= 0.9.4.1 - Information Disclosure Race Condition
W3 Total Cache <= 0.9.4.1 - Weak Validation of Amazon SNS Push Messages
W3 Total Cache <= 0.9.7.3 - Cross-Site Scripting (XSS)
W3 Total Cache < 0.9.7.4 - Blind SSRF and RCE via phar
W3 Total Cache < 0.9.7.3 - Cryptographic Signature Bypass
WordPress W3 Total Cache plugin <= 0.9.2.8 - PHP Code Execution vulnerability
WordPress W3 Total Cache Plugin <= 0.9.4 - Cross Site Request Forgery
WordPress W3 Total Cache Plugin <= 0.9.4.1 - Reflected Cross Site Scripting
WordPress W3 Total Cache Plugin <= 0.9.4.1 - Arbitrary PHP Code Execution
WordPress W3 Total Cache Plugin <= 0.9.4.1 - Arbitrary File Download
WordPress W3 Total Cache Plugin <= 0.9.4.1 - Arbitrary File Upload
WordPress W3 Total Cache Plugin <= 0.9.4.1 - Bypass
WordPress W3 Total Cache plugin <= 0.9.7.3 - Cross-Site Scripting (XSS) vulnerability
CVE-2014-8724
CVE-2014-9414
W3 Total Cache 0.9.2.6-0.9.3 - File Read / Directory Traversal
CVE-2013-2010
CVE-2021-24427
CVE-2021-24436
CVE-2021-24452