Vulnerabilities (CVE)

Filtered by vendor Wuzhicms Subscribe
Filtered by product Wuzhi Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-27431 1 Wuzhicms 1 Wuzhi Cms 2022-05-11 7.5 HIGH 9.8 CRITICAL
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.
CVE-2020-20122 1 Wuzhicms 1 Wuzhi Cms 2021-10-06 7.5 HIGH 9.8 CRITICAL
Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.
CVE-2018-11528 1 Wuzhicms 1 Wuzhi Cms 2018-06-28 7.5 HIGH 9.8 CRITICAL
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.