Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-3563 A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachm… Wuzhicms No fix yet Fix from $1,9502025-04-14 MEDIUM 5.4 CVE-2025-25916 wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php. Wuzhicms No fix yet Fix from $1,6002025-02-28 HIGH 7.2 CVE-2024-10505 A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/cont… Wuzhicms No fix yet Fix from $1,9502024-10-30 MEDIUM 6.5 CVE-2024-31008 An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php fi… Wuzhicms No fix yet Fix from $1,6002024-04-03 CRITICAL 9.8 CVE-2023-52064 Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php. Wuzhicms No fix yet Fix from $2,3002024-01-10 CRITICAL 9.8 CVE-2023-46482 SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coref… Wuzhicms No fix yet Fix from $2,3002023-11-01 HIGH 8.8 CVE-2020-36037 An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index… Wuzhicms No fix yet Fix from $1,9502023-08-11 HIGH 8.8 CVE-2020-21325 An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file. Wuzhicms No fix yet Fix from $1,9502023-06-20 CRITICAL 9.8 CVE-2020-20413 SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/conte… Wuzhicms No fix yet Fix from $2,3002023-06-20 MEDIUM 5.4 CVE-2023-31860 Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system. Wuzhicms No fix yet Fix from $1,6002023-05-23 MEDIUM 5.4 CVE-2023-30123 wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings. Wuzhicms No fix yet Fix from $1,6002023-04-28 MEDIUM 6.1 CVE-2020-19897 A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter. Wuzhicms No fix yet Fix from $1,6002022-06-28 CRITICAL 9.8 CVE-2021-41654 SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coref… Wuzhicms No fix yet Fix from $2,3002022-06-16 CRITICAL 9.8 CVE-2022-27431 Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php. Wuzhicms No fix yet Fix from $2,3002022-05-04 MEDIUM 5.4 CVE-2020-19770 A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie. Wuzhicms No fix yet Fix from $1,6002021-12-21 HIGH 7.5 CVE-2020-28145 Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to acce… Wuzhicms No fix yet Fix from $1,9502021-10-12 CRITICAL 9.8 CVE-2020-20122 Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php. Wuzhicms No fix yet Fix from $2,3002021-09-28 HIGH 8.8 CVE-2020-20124 Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php. Wuzhicms No fix yet Fix from $1,9502021-09-28 HIGH 8.1 CVE-2020-24930 Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five fingers CMS backend in***.php file … Wuzhicms No fix yet Fix from $1,9502021-09-27 MEDIUM 6.1 CVE-2020-19915 Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php. Wuzhicms No fix yet Fix from $1,6002021-09-20 CRITICAL 9.8 CVE-2021-40674 An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php. Wuzhicms No fix yet Fix from $2,3002021-09-20 CRITICAL 9.8 CVE-2021-40669 SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file. Wuzhicms No fix yet Fix from $2,3002021-09-16 CRITICAL 9.8 CVE-2021-40670 SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file. Wuzhicms No fix yet Fix from $2,3002021-09-16 HIGH 7.5 CVE-2020-18877 SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/o… Wuzhicms No fix yet Fix from $1,9502021-08-20 MEDIUM 6.1 CVE-2020-18654 Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/corefra… Wuzhicms No fix yet Fix from $1,6002021-06-22 MEDIUM 5.4 CVE-2018-17425 WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI. Wuzhicms No fix yet Fix from $1,6002019-03-07 MEDIUM 5.4 CVE-2018-17426 WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI. Wuzhicms No fix yet Fix from $1,6002019-03-07 MEDIUM 6.1 CVE-2019-9107 XSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imagecut.php. Wuzhicms No fix yet Fix from $1,6002019-02-25 MEDIUM 6.1 CVE-2019-9108 XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php. Wuzhicms No fix yet Fix from $1,6002019-02-25 MEDIUM 6.1 CVE-2019-9109 XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.php. Wuzhicms No fix yet Fix from $1,6002019-02-25