Show filters
53 Total Results
Displaying 11-20 of 53
Sort by:
Attacker Value
Unknown

CVE-2021-41654

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
Attacker Value
Unknown

CVE-2022-27431

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.
Attacker Value
Unknown

CVE-2020-19770

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.
Attacker Value
Unknown

CVE-2020-28145

Disclosure Date: October 12, 2021 (last updated February 23, 2025)
Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.
Attacker Value
Unknown

CVE-2020-20122

Disclosure Date: September 28, 2021 (last updated February 23, 2025)
Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.
Attacker Value
Unknown

CVE-2020-20124

Disclosure Date: September 28, 2021 (last updated February 23, 2025)
Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
Attacker Value
Unknown

CVE-2020-24930

Disclosure Date: September 27, 2021 (last updated November 29, 2024)
Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five fingers CMS backend in***.php file has arbitrary file deletion vulnerability. Attackers can use vulnerabilities to delete arbitrary files.
Attacker Value
Unknown

CVE-2020-19553

Disclosure Date: September 21, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php.
Attacker Value
Unknown

CVE-2020-19551

Disclosure Date: September 21, 2021 (last updated February 23, 2025)
Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.
Attacker Value
Unknown

CVE-2020-19915

Disclosure Date: September 20, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.