Wuzhicms

Wuzhicms

63 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 22.09.2026 00:00:00
  • Zuletzt bearbeitet 24.09.2026 21:25:27

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary P...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 21.09.2026 01:00:10
  • Zuletzt bearbeitet 24.09.2026 14:18:19

A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login of the component Login. This manipulation of the argument forward causes open redirect. The attack can be initiated remotely. The ...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 16.09.2026 14:30:09
  • Zuletzt bearbeitet 16.09.2026 17:53:40

A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes server-side ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 15.09.2026 15:30:07
  • Zuletzt bearbeitet 17.09.2026 16:18:29

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted ...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 15.09.2026 15:15:06
  • Zuletzt bearbeitet 16.09.2026 17:53:40

A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads to sql injecti...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 13.07.2026 04:00:08
  • Zuletzt bearbeitet 13.07.2026 19:16:59

A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component Attachment API. Executing a manipulation can lead to information disc...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 14.04.2025 11:00:12
  • Zuletzt bearbeitet 29.04.2025 20:25:59

A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachment&f=index&_su=wuzhicms&v=set&submit=1 of the component Setting Handler. The manipulation of the arg...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 28.02.2025 15:15:13
  • Zuletzt bearbeitet 29.04.2025 16:53:21

wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 15.01.2025 18:15:24
  • Zuletzt bearbeitet 13.05.2025 13:39:11

A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery....

Exploit
  • EPSS 0.71%
  • Veröffentlicht 30.10.2024 02:15:02
  • Zuletzt bearbeitet 06.11.2024 16:38:28

A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack re...