Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Wuzhicms MEDIUM 6.1
CVE-2019-9110

XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.

No fix yet
Fix from $1,600 2019-02-25
Wuzhicms CRITICAL 9.8
CVE-2018-20572

WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a relat…

No fix yet
Fix from $2,300 2018-12-28
Wuzhicms HIGH 8.8
CVE-2018-18712

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f…

No fix yet
Fix from $1,950 2018-10-29
Wuzhicms HIGH 8.8
CVE-2018-18711

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=p…

No fix yet
Fix from $1,950 2018-10-29
Wuzhi Cms MEDIUM 6.1
CVE-2018-17832

XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.

No fix yet
Fix from $1,600 2018-10-01
Wuzhicms MEDIUM 6.1
CVE-2018-14512

An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML v…

No fix yet
Fix from $1,600 2018-07-23
Wuzhicms HIGH 7.2
CVE-2018-14472

An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly int…

No fix yet
Fix from $1,950 2018-07-20
Wuzhicms CRITICAL 9.8
CVE-2018-11722

WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.

No fix yet
Fix from $2,300 2018-06-05
Wuzhicms MEDIUM 5.4
CVE-2018-11549

An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordina…

No fix yet
Fix from $1,600 2018-05-29
Wuzhicms CRITICAL 9.8
CVE-2018-11528

WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.

No fix yet
Fix from $2,300 2018-05-29
Wuzhicms HIGH 8.8
CVE-2018-11493

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.

No fix yet
Fix from $1,950 2018-05-26
Wuzhicms HIGH 8.8
CVE-2018-10312

index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.

No fix yet
Fix from $1,950 2018-04-24
Wuzhicms MEDIUM 6.1
CVE-2018-10311

A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via th…

No fix yet
Fix from $1,600 2018-04-24
Wuzhicms MEDIUM 5.4
CVE-2018-10313

WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.

No fix yet
Fix from $1,600 2018-04-24
Wuzhicms MEDIUM 6.5
CVE-2018-10248

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_del…

No fix yet
Fix from $1,600 2018-04-20
Wuzhicms MEDIUM 5.4
CVE-2018-10221

An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parame…

No fix yet
Fix from $1,600 2018-04-19
Wuzhicms HIGH 8.8
CVE-2018-9926

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.

No fix yet
Fix from $1,950 2018-04-10
Wuzhicms HIGH 8.8
CVE-2018-9927

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.

No fix yet
Fix from $1,950 2018-04-10