Known Vulnerabilities for Wps Office by Kingsoft
Listed below are 7 of the newest known vulnerabilities associated with "Wps Office" by "Kingsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103590 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of... | Not Provided | 2026-09-30 | 2026-10-01 |
| CVE-2026-103589 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails ... | Not Provided | 2026-09-30 | 2026-10-01 |
| CVE-2026-103588 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Tran... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103587 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Boo... | Not Provided | 2026-09-30 | 2026-10-01 |
| CVE-2026-102364 json | mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-100640 json | SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to ... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-100208 json | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-09-25 | 2026-09-29 |
| CVE-2026-94104 json | NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to val... | Not Provided | 2026-09-20 | 2026-09-24 |
| CVE-2026-93988 json | QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authen... | Not Provided | 2026-09-19 | 2026-09-21 |
| CVE-2026-92463 json | yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAutho... | Not Provided | 2026-09-16 | 2026-09-18 |