Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Wuzhicms Subscribe
Filtered by product Wuzhi Cms
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10391 1 Wuzhicms 1 Wuzhi Cms 2018-05-24 3.5 LOW 4.8 MEDIUM
An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.
CVE-2018-10367 1 Wuzhicms 1 Wuzhi Cms 2018-05-24 3.5 LOW 4.8 MEDIUM
An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.
CVE-2018-10311 1 Wuzhicms 1 Wuzhi Cms 2018-05-24 4.3 MEDIUM 6.1 MEDIUM
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.
CVE-2018-10313 1 Wuzhicms 1 Wuzhi Cms 2018-05-23 3.5 LOW 5.4 MEDIUM
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.
CVE-2018-10248 1 Wuzhicms 1 Wuzhi Cms 2018-05-21 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.