Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wuzhicms wuzhi cms 4.1.0 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-27431
Wuzhicms v4.1.0 exists to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.
Wuzhicms Wuzhi Cms 4.1.0
6.1
CVSSv3
CVE-2019-9107
XSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imagecut.php.
Wuzhicms Wuzhi Cms 4.1.0
4.8
CVSSv3
CVE-2018-10367
An issue exists in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.
Wuzhicms Wuzhi Cms 4.1.0
4.8
CVSSv3
CVE-2018-10368
An issue exists in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.
Wuzhicms Wuzhi Cms 4.1.0
4.8
CVSSv3
CVE-2018-10391
An issue exists in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.
Wuzhicms Wuzhi Cms 4.1.0
6.1
CVSSv3
CVE-2019-9110
XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.
Wuzhicms Wuzhi Cms 4.1.0
5.4
CVSSv3
CVE-2020-19770
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows malicious users to steal the admin's cookie.
Wuzhicms Wuzhi Cms 4.1.0
6.1
CVSSv3
CVE-2020-19897
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote malicious users to execute arbitrary web script or HTML via the imgurl parameter.
Wuzhicms Wuzhi Cms 4.1.0
9.8
CVSSv3
CVE-2020-20122
Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.
Wuzhicms Wuzhi Cms 4.1.0
9.8
CVSSv3
CVE-2023-52064
Wuzhicms v4.1.0 exists to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.
Wuzhicms Wuzhi Cms 4.1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4651
CVE-2024-34255
elevation of privilege
CVE-2024-25529
CVE-2024-4671
NULL pointer dereference
CVE-2024-25527
template injection
CVE-2008-0166
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »