CVE-2026-88419
- EPSS 0.48%
- Veröffentlicht 22.09.2026 00:00:00
- Zuletzt bearbeitet 24.09.2026 21:25:27
An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary P...
- EPSS 0.25%
- Veröffentlicht 21.09.2026 01:00:10
- Zuletzt bearbeitet 24.09.2026 14:18:19
A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login of the component Login. This manipulation of the argument forward causes open redirect. The attack can be initiated remotely. The ...
CVE-2026-92380
- EPSS 0.47%
- Veröffentlicht 16.09.2026 14:30:09
- Zuletzt bearbeitet 16.09.2026 17:53:40
A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes server-side ...
CVE-2026-91849
- EPSS 0.27%
- Veröffentlicht 15.09.2026 15:30:07
- Zuletzt bearbeitet 17.09.2026 16:18:29
A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted ...
CVE-2026-91848
- EPSS 0.46%
- Veröffentlicht 15.09.2026 15:15:06
- Zuletzt bearbeitet 16.09.2026 17:53:40
A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads to sql injecti...
CVE-2026-15530
- EPSS 0.31%
- Veröffentlicht 13.07.2026 04:00:08
- Zuletzt bearbeitet 13.07.2026 19:16:59
A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component Attachment API. Executing a manipulation can lead to information disc...
CVE-2025-3563
- EPSS 0.64%
- Veröffentlicht 14.04.2025 11:00:12
- Zuletzt bearbeitet 29.04.2025 20:25:59
A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachment&f=index&_su=wuzhicms&v=set&submit=1 of the component Setting Handler. The manipulation of the arg...
CVE-2025-25916
- EPSS 0.23%
- Veröffentlicht 28.02.2025 15:15:13
- Zuletzt bearbeitet 29.04.2025 16:53:21
wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.
CVE-2025-0480
- EPSS 0.5%
- Veröffentlicht 15.01.2025 18:15:24
- Zuletzt bearbeitet 13.05.2025 13:39:11
A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery....
CVE-2024-10505
- EPSS 0.71%
- Veröffentlicht 30.10.2024 02:15:02
- Zuletzt bearbeitet 06.11.2024 16:38:28
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack re...