Vulnerabilities (CVE)

Filtered by vendor Wuzhicms Subscribe
Filtered by product Wuzhi Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-20124 1 Wuzhicms 1 Wuzhi Cms 2022-07-10 6.5 MEDIUM 8.8 HIGH
Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
CVE-2018-18711 1 Wuzhicms 1 Wuzhi Cms 2018-11-16 6.8 MEDIUM 8.8 HIGH
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.
CVE-2018-18712 1 Wuzhicms 1 Wuzhi Cms 2018-11-16 6.8 MEDIUM 8.8 HIGH
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.
CVE-2018-11493 1 Wuzhicms 1 Wuzhi Cms 2018-06-29 6.8 MEDIUM 8.8 HIGH
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.
CVE-2018-10312 1 Wuzhicms 1 Wuzhi Cms 2018-05-24 6.8 MEDIUM 8.8 HIGH
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.