CVE-2025-3563
- EPSS 0.04%
- Veröffentlicht 14.04.2025 11:00:12
- Zuletzt bearbeitet 29.04.2025 20:25:59
A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachment&f=index&_su=wuzhicms&v=set&submit=1 of the component Setting Handler. The manipulation of the arg...
CVE-2025-25916
- EPSS 0.04%
- Veröffentlicht 28.02.2025 15:15:13
- Zuletzt bearbeitet 29.04.2025 16:53:21
wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.
CVE-2025-0480
- EPSS 0.08%
- Veröffentlicht 15.01.2025 18:15:24
- Zuletzt bearbeitet 13.05.2025 13:39:11
A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery....
CVE-2024-10505
- EPSS 0.28%
- Veröffentlicht 30.10.2024 02:15:02
- Zuletzt bearbeitet 06.11.2024 16:38:28
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack re...
CVE-2024-32206
- EPSS 0.23%
- Veröffentlicht 19.04.2024 16:15:10
- Zuletzt bearbeitet 05.05.2025 18:14:23
A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.
CVE-2024-31008
- EPSS 0.18%
- Veröffentlicht 03.04.2024 06:15:07
- Zuletzt bearbeitet 13.05.2025 01:10:52
An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.
CVE-2023-52064
- EPSS 0.14%
- Veröffentlicht 10.01.2024 21:15:09
- Zuletzt bearbeitet 03.06.2025 15:15:49
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.
CVE-2023-46482
- EPSS 1.96%
- Veröffentlicht 01.11.2023 19:15:45
- Zuletzt bearbeitet 21.11.2024 08:28:34
SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.
CVE-2020-36037
- EPSS 0.32%
- Veröffentlicht 11.08.2023 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:28:41
An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.
CVE-2020-21325
- EPSS 1.09%
- Veröffentlicht 20.06.2023 15:15:11
- Zuletzt bearbeitet 09.12.2024 22:15:20
An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.