Vulnerabilities (CVE)

Filtered by vendor Wuzhicms Subscribe
Filtered by product Wuzhicms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-19553 1 Wuzhicms 1 Wuzhicms 2021-09-29 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php.
CVE-2020-19915 1 Wuzhicms 1 Wuzhicms 2021-09-29 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.
CVE-2020-18654 1 Wuzhicms 1 Wuzhicms 2021-06-24 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".
CVE-2020-21590 1 Wuzhicms 1 Wuzhicms 2021-04-08 4.0 MEDIUM 4.3 MEDIUM
Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter.
CVE-2019-9108 1 Wuzhicms 1 Wuzhicms 2019-02-25 4.3 MEDIUM 6.1 MEDIUM
XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php.
CVE-2018-10221 1 Wuzhicms 1 Wuzhicms 2018-05-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lower than the administrator) logs in, he can add a new TAGS with the XSS payload.