Known Vulnerabilities for Wuzhicms by Wuzhicms
Listed below are 10 of the newest known vulnerabilities associated with "Wuzhicms" by "Wuzhicms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-92380 json | A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-91849 json | A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.p... | Not Provided | 2026-09-15 | 2026-09-17 |
| CVE-2026-91848 json | A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the ... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-15530 json | A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /i... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2024-32206 json | A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attacke... | Not Provided | 2024-04-19 | 2026-07-09 |
| CVE-2023-46482 json | SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Fu... | 9.8 - CRITICAL | 2023-11-01 | 2023-11-09 |
| CVE-2023-30123 json | wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings. | 5.4 - MEDIUM | 2023-04-28 | 2023-05-05 |
| CVE-2022-36168 json | A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php: | 2.7 - LOW | 2022-08-26 | 2022-08-31 |
| CVE-2021-41654 json | SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyV... | 9.8 - CRITICAL | 2022-06-16 | 2022-06-27 |
| CVE-2021-40674 json | An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php. | 9.8 - CRITICAL | 2021-09-20 | 2021-09-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wuzhicms | Wuzhicms | 4.1.0 | |||
| Application | Wuzhicms | Wuzhicms | 4.0.0 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.3 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.2 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.1 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.0.2 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.0.1 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.0 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.4.0 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.4 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.3.0 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.3 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.1 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.0 | |||
| Application | Wuzhicms | Wuzhicms | 2.1.7 | |||
| Application | Wuzhicms | Wuzhicms | 2.1.6 | |||
| Application | Wuzhicms | Wuzhicms | 2.1.3 | |||
| Application | Wuzhicms | Wuzhicms | 2.1.2 | |||
| Application | Wuzhicms | Wuzhicms | 2.0.5 | |||
| Application | Wuzhicms | Wuzhicms | 2.0.4 |