« Back to list

Wang.market

Wang.market Wangmarket: vulnerabilities and CVEs

Wang.market Wangmarket has 8 published vulnerabilities, 4 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months4
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-15452Low (1.9)0.28%—Jan 5, 2026
A weakness has been identified in xnx3 wangmarket up to 4.9. This affects the function variableList of the file /admin/system/variableList.do of the component Backend Variable Search. Executing a manipulation of the…
CVE-2025-15451Low (1.9)0.28%—Jan 5, 2026
A security flaw has been discovered in xnx3 wangmarket up to 4.9. Affected by this issue is some unknown functionality of the file /admin/system/variableSave.do of the component System Variables Page. Performing a…
CVE-2025-15416Low (1.9)0.27%—Jan 1, 2026
A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of the component Add Global Variable Handler. The manipulation of the argument Remark/Variable Value…
CVE-2025-15415Low (2)0.25%—Jan 1, 2026
A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the component XML File Handler. The manipulation of the argument image…
CVE-2025-25770Medium (6.8)0.23%—Feb 21, 2025
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java.
CVE-2025-25769High (8)0.19%—Feb 21, 2025
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java.
CVE-2023-6886Critical (9.8)0.85%—Dec 17, 2023
A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Role Management Page. The manipulation leads to code injection. The…
CVE-2023-26813Critical (9.8)0.97%—Apr 28, 2023
SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1185 Browser Session Hijacking1
  2. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.