Show filters
52 Total Results
Displaying 21-30 of 52
Sort by:
Attacker Value
Unknown

CVE-2022-44140

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
Attacker Value
Unknown

CVE-2021-29334

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
An issue was discovered in JIZHI CMS 1.9.4. There is a CSRF vulnerability that can add an admin account via index, /admin.php/Admin/adminadd.html
Attacker Value
Unknown

CVE-2022-36168

Disclosure Date: August 26, 2022 (last updated February 24, 2025)
A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:
Attacker Value
Unknown

CVE-2022-36578

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
jizhicms v2.3.1 has SQL injection in the background.
Attacker Value
Unknown

CVE-2022-36577

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
Attacker Value
Unknown

CVE-2021-41654

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
Attacker Value
Unknown

CVE-2022-31393

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.php.
Attacker Value
Unknown

CVE-2022-31390

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateController.php.
Attacker Value
Unknown

CVE-2022-27429

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.
Attacker Value
Unknown

CVE-2020-28145

Disclosure Date: October 12, 2021 (last updated February 23, 2025)
Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.