Known Vulnerabilities for Wuzhicms by Wuzhicms
Listed below are 10 of the newest known vulnerabilities associated with "Wuzhicms" by "Wuzhicms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-46482 json | SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Fu... | 9.8 - CRITICAL | 2023-11-01 | 2023-11-09 |
| CVE-2023-30123 json | wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings. | 5.4 - MEDIUM | 2023-04-28 | 2023-05-05 |
| CVE-2022-36168 json | A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php: | 2.7 - LOW | 2022-08-26 | 2022-08-31 |
| CVE-2021-41654 json | SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyV... | 9.8 - CRITICAL | 2022-06-16 | 2022-06-27 |
| CVE-2021-40674 json | An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php. | 9.8 - CRITICAL | 2021-09-20 | 2021-09-28 |
| CVE-2021-40670 json | SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.p... | 9.8 - CRITICAL | 2021-09-16 | 2021-09-27 |
| CVE-2021-40669 json | SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.... | 9.8 - CRITICAL | 2021-09-16 | 2021-09-27 |
| CVE-2020-36037 json | An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter... | 8.8 - HIGH | 2023-08-11 | 2023-08-15 |
| CVE-2020-28145 json | Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which ... | 7.5 - HIGH | 2021-10-12 | 2021-10-18 |
| CVE-2020-24930 json | Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five fingers CMS... | 8.1 - HIGH | 2021-09-27 | 2021-10-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wuzhicms | Wuzhicms | 4.1.0 | |||
| Application | Wuzhicms | Wuzhicms | 4.0.0 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.3 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.2 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.1 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.0.2 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.0.1 | |||
| Application | Wuzhicms | Wuzhicms | 3.1.0 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.4.0 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.4 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.3.0 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.3 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.1 | |||
| Application | Wuzhicms | Wuzhicms | 3.0.0 | |||
| Application | Wuzhicms | Wuzhicms | 2.1.7 | |||
| Application | Wuzhicms | Wuzhicms | 2.1.6 | |||
| Application | Wuzhicms | Wuzhicms | 2.1.3 | |||
| Application | Wuzhicms | Wuzhicms | 2.1.2 | |||
| Application | Wuzhicms | Wuzhicms | 2.0.5 | |||
| Application | Wuzhicms | Wuzhicms | 2.0.4 |