CPE
Authenticated backend users with template-editing privileges can bypass the Winter CMS Twig sandbox to execute arbitrary PHP or SQL, stemming from an incomplete fix for CVE-2024-54149.