CVE-2026-2141
- EPSS 0.36%
- Veröffentlicht 08.02.2026 07:32:06
- Zuletzt bearbeitet 14.07.2026 15:02:10
A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a man...
CVE-2025-60828
- EPSS 0.33%
- Veröffentlicht 08.10.2025 00:00:00
- Zuletzt bearbeitet 14.07.2026 15:06:01
WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.
CVE-2025-8852
- EPSS 0.35%
- Veröffentlicht 11.08.2025 14:02:05
- Zuletzt bearbeitet 14.07.2026 15:06:01
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible ...
CVE-2025-5521
- EPSS 0.28%
- Veröffentlicht 03.06.2025 18:31:04
- Zuletzt bearbeitet 14.07.2026 15:06:01
A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/user/updataPassword. The manipulation leads to cross-site request forgery...
CVE-2024-23052
- EPSS 4.87%
- Veröffentlicht 29.02.2024 01:44:07
- Zuletzt bearbeitet 14.07.2026 15:06:01
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.