Wuzhicms

Wuzhicms

57 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.58%
  • Published 20.06.2023 15:15:10
  • Last modified 10.12.2024 20:15:06

SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

Exploit
  • EPSS 0.08%
  • Published 23.05.2023 20:15:10
  • Last modified 05.05.2025 18:10:51

Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system.

Exploit
  • EPSS 0.08%
  • Published 28.04.2023 14:15:11
  • Last modified 30.01.2025 20:15:31

wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings.

Exploit
  • EPSS 0.45%
  • Published 26.08.2022 00:15:09
  • Last modified 21.11.2024 07:12:31

A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:

Exploit
  • EPSS 0.27%
  • Published 28.06.2022 22:15:07
  • Last modified 05.05.2025 18:10:51

A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.

Exploit
  • EPSS 0.27%
  • Published 16.06.2022 12:15:10
  • Last modified 21.11.2024 06:26:35

SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php

Exploit
  • EPSS 0.23%
  • Published 04.05.2022 03:15:07
  • Last modified 05.05.2025 18:10:51

Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.

Exploit
  • EPSS 0.19%
  • Published 21.12.2021 18:15:07
  • Last modified 05.05.2025 18:10:51

A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.

Exploit
  • EPSS 0.3%
  • Published 12.10.2021 11:15:07
  • Last modified 21.11.2024 05:22:24

Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.

Exploit
  • EPSS 3.15%
  • Published 28.09.2021 23:15:07
  • Last modified 05.05.2025 18:10:51

Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.