Wuzhicms

Wuzhicms

63 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.39%
  • Veröffentlicht 19.04.2024 16:15:10
  • Zuletzt bearbeitet 09.07.2026 01:19:01

A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 03.04.2024 06:15:07
  • Zuletzt bearbeitet 13.05.2025 01:10:52

An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.

Exploit
  • EPSS 0.64%
  • Veröffentlicht 10.01.2024 21:15:09
  • Zuletzt bearbeitet 03.06.2025 15:15:49

Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.

Exploit
  • EPSS 1.16%
  • Veröffentlicht 01.11.2023 19:15:45
  • Zuletzt bearbeitet 21.11.2024 08:28:34

SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.

Exploit
  • EPSS 1.05%
  • Veröffentlicht 11.08.2023 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:28:41

An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.

Exploit
  • EPSS 1.26%
  • Veröffentlicht 20.06.2023 15:15:11
  • Zuletzt bearbeitet 09.12.2024 22:15:20

An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.

Exploit
  • EPSS 1.34%
  • Veröffentlicht 20.06.2023 15:15:10
  • Zuletzt bearbeitet 10.12.2024 20:15:06

SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 23.05.2023 20:15:10
  • Zuletzt bearbeitet 05.05.2025 18:10:51

Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 28.04.2023 14:15:11
  • Zuletzt bearbeitet 30.01.2025 20:15:31

wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings.

Exploit
  • EPSS 0.81%
  • Veröffentlicht 26.08.2022 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:12:31

A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php: