WuzhicmsCVEs & Vulnerabilities

58 CVEs affecting Wuzhicms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wuzhicms 57wuzhi cms 1
CVE-2025-3563HIGH

A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachment&f=index&_su=wuzhicms&v=set&submit=1 of the component Setting Handler. The manipulation of the argument Setting leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

14 Apr 2025
7.2
CVSS
CVE-2025-25916MEDIUM

wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.

28 Feb 2025
5.4
CVSS
CVE-2025-0480MEDIUM

A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

15 Jan 2025
4.3
CVSS
CVE-2024-10505HIGH

A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Initially two separate issues were created by the researcher for the different function calls. The vendor was contacted early about this disclosure but did not respond in any way.

30 Oct 2024
7.2
CVSS
CVE-2024-32206MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.

19 Apr 2024
4.6
CVSS
CVE-2024-31008MEDIUM

An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.

3 Apr 2024
6.5
CVSS
CVE-2023-52064CRITICAL

Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.

11 Jan 2024
9.8
CVSS
CVE-2023-46482CRITICAL

SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.

1 Nov 2023
9.8
CVSS
CVE-2020-36037HIGH

An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.

11 Aug 2023
8.8
CVSS
CVE-2020-21325HIGH

An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.

20 Jun 2023
8.8
CVSS
CVE-2020-20413CRITICAL

SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

20 Jun 2023
9.8
CVSS
CVE-2023-31860MEDIUM

Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system.

23 May 2023
5.4
CVSS
CVE-2023-30123MEDIUM

wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings.

28 Apr 2023
5.4
CVSS
CVE-2022-36168LOW

A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:

26 Aug 2022
2.7
CVSS
CVE-2020-19897MEDIUM

A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.

29 Jun 2022
6.1
CVSS
CVE-2021-41654CRITICAL

SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php

16 Jun 2022
9.8
CVSS
CVE-2022-27431CRITICAL

Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.

4 May 2022
9.8
CVSS
CVE-2020-19770MEDIUM

A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.

21 Dec 2021
5.4
CVSS
CVE-2020-28145HIGH

Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.

12 Oct 2021
7.5
CVSS
CVE-2020-20124HIGH

Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.

29 Sep 2021
8.8
CVSS
CVE-2020-20122CRITICAL

Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.

29 Sep 2021
9.8
CVSS
CVE-2020-24930HIGH

Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five fingers CMS backend in***.php file has arbitrary file deletion vulnerability. Attackers can use vulnerabilities to delete arbitrary files.

28 Sep 2021
8.1
CVSS
CVE-2020-19553MEDIUM

Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php.

21 Sep 2021
5.4
CVSS
CVE-2020-19551HIGH

Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.

21 Sep 2021
8.8
CVSS
CVE-2020-19915MEDIUM

Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.

20 Sep 2021
6.1
CVSS
CVE-2021-40674CRITICAL

An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.

20 Sep 2021
9.8
CVSS
CVE-2021-40670CRITICAL

SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file.

16 Sep 2021
9.8
CVSS
CVE-2021-40669CRITICAL

SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file.

16 Sep 2021
9.8
CVSS
CVE-2020-18877HIGH

SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.

20 Aug 2021
7.5
CVSS
CVE-2020-18654MEDIUM

Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".

22 Jun 2021
6.1
CVSS
CVE-2020-21590MEDIUM

Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter.

2 Apr 2021
4.3
CVSS
CVE-2018-17426MEDIUM

WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.

8 Mar 2019
5.4
CVSS
CVE-2018-17425MEDIUM

WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.

8 Mar 2019
5.4
CVSS
CVE-2019-9110MEDIUM

XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.

25 Feb 2019
6.1
CVSS
CVE-2019-9109MEDIUM

XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.php.

25 Feb 2019
6.1
CVSS
CVE-2019-9108MEDIUM

XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php.

25 Feb 2019
6.1
CVSS
CVE-2019-9107MEDIUM

XSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imagecut.php.

25 Feb 2019
6.1
CVSS
CVE-2018-20572CRITICAL

WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.

28 Dec 2018
9.8
CVSS
CVE-2018-18938MEDIUM

An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.

5 Nov 2018
4.8
CVSS
CVE-2018-18712HIGH

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.

29 Oct 2018
8.8
CVSS
CVE-2018-18711HIGH

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.

29 Oct 2018
8.8
CVSS
CVE-2018-17832MEDIUMpoc

XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.

1 Oct 2018
6.1
CVSS
CVE-2018-14512MEDIUM

An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.

23 Jul 2018
6.1
CVSS
CVE-2018-14472HIGH

An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.

20 Jul 2018
7.2
CVSS
CVE-2018-11722CRITICAL

WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.

5 Jun 2018
9.8
CVSS
CVE-2018-11549MEDIUM

An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.

30 May 2018
5.4
CVSS
CVE-2018-11528CRITICAL

WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.

29 May 2018
9.8
CVSS
CVE-2018-11493HIGH

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.

26 May 2018
8.8
CVSS
← PrevPage 1 / 2Next →