WuzhicmsCVEs & Vulnerabilities

58 CVEs affecting Wuzhicms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wuzhicms 57wuzhi cms 1
CVE-2018-10391MEDIUM

An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.

26 Apr 2018
4.8
CVSS
CVE-2018-10368MEDIUM

An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.

25 Apr 2018
4.8
CVSS
CVE-2018-10367MEDIUM

An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.

25 Apr 2018
4.8
CVSS
CVE-2018-10313MEDIUMpoc

WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.

24 Apr 2018
5.4
CVSS
CVE-2018-10312HIGHpoc

index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.

24 Apr 2018
8.8
CVSS
CVE-2018-10311MEDIUMpoc

A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.

24 Apr 2018
6.1
CVSS
CVE-2018-10248MEDIUM

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.

20 Apr 2018
6.5
CVSS
CVE-2018-10221MEDIUM

An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lower than the administrator) logs in, he can add a new TAGS with the XSS payload.

19 Apr 2018
5.4
CVSS
CVE-2018-9927HIGH

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.

10 Apr 2018
8.8
CVSS
CVE-2018-9926HIGHpoc

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.

10 Apr 2018
8.8
CVSS
← PrevPage 2 / 2Next →
Wuzhicms CVEs & Vulnerabilities — 58 Tracked — Page 2