Wuzhi CMS Project
Wuzhi CMS Project Wuzhi CMS: vulnerabilidades y CVE
Wuzhi CMS Project Wuzhi CMS tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-18939 | Media (4.8) | 0.67% | — | 5 nov 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field. |
| CVE-2018-17852 | Crítica (9.8) | 1.5% | — | 1 oct 2018 | A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI. |
| CVE-2018-16350 | Media (6.1) | 0.86% | — | 2 sept 2018 | WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter. |
| CVE-2018-16349 | Media (6.1) | 0.86% | — | 2 sept 2018 | WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter. |
| CVE-2018-15894 | Crítica (9.8) | 1.5% | — | 27 ago 2018 | A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing keyValue parameter. |
| CVE-2018-15893 | Crítica (9.8) | 1.5% | — | 27 ago 2018 | A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing keywords parameter. |
| CVE-2018-14515 | Crítica (9.8) | 2.0% | — | 23 jul 2018 | A SQL injection was discovered in WUZHI CMS 4.1.0 that allows remote attackers to inject a malicious SQL statement via the index.php?m=promote&f=index&v=search keywords parameter. |
| CVE-2018-14513 | Media (6.1) | 1.1% | — | 23 jul 2018 | An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[content] parameter to the… |