📦 Wuzhicms

by Wuzhicms

🔍 What is Wuzhicms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-52064

CRITICAL CVSS 9.8 Jan 10, 2024

Wuzhicms v4.1.0 contains a SQL injection vulnerability in the $keywords parameter at /core/admin/copyfrom.php. This allows attackers to execute arbitrary SQL commands on the database. All users runnin...

CVE-2023-46482

CRITICAL CVSS 9.8 Nov 1, 2023

This SQL injection vulnerability in wuzhicms v4.1.0 allows remote attackers to execute arbitrary SQL commands through the database backup functionality. Attackers can potentially read, modify, or dele...

CVE-2020-20413

CRITICAL CVSS 9.8 Jun 20, 2023

This SQL injection vulnerability in WUZHICMS v4.1.0 allows remote attackers to execute arbitrary SQL commands through the checktitle() function in admin/content.php. Attackers can potentially access, ...

CVE-2021-40674

CRITICAL CVSS 9.8 Sep 20, 2021

This SQL injection vulnerability in Wuzhi CMS v4.1.0 allows attackers to execute arbitrary SQL commands via the KeyValue parameter in the order administration interface. Attackers can potentially acce...

CVE-2021-40669

CRITICAL CVSS 9.8 Sep 16, 2021

This SQL injection vulnerability in Wuzhi CMS 4.1.0 allows attackers to execute arbitrary SQL commands through the keywords parameter in the admin interface. This affects all deployments running the v...

CVE-2020-21325

HIGH CVSS 8.8 Jun 20, 2023

This vulnerability allows remote attackers to execute arbitrary code on WUZHI CMS systems via an unsafe file upload mechanism in the set_chache method. Attackers can upload malicious files that get ex...

CVE-2020-20124

HIGH CVSS 8.8 Sep 28, 2021

CVE-2020-20124 is a remote code execution vulnerability in Wuzhi CMS v4.1.0 that allows attackers to execute arbitrary code on affected systems through the \attachment\admin\index.php file. This affec...

CVE-2020-24930

HIGH CVSS 8.1 Sep 27, 2021

CVE-2020-24930 is an arbitrary file deletion vulnerability in Wuzhi CMS 4.0.1 backend. Attackers can delete any files on the server, potentially causing service disruption or data loss. This affects a...

CVE-2020-19551

HIGH CVSS 8.8 Sep 21, 2021

This vulnerability allows attackers to bypass file upload blacklists in WUZHI CMS, potentially leading to remote code execution. It affects all WUZHI CMS installations up to version 4.1.0. Attackers c...

CVE-2020-18877

HIGH CVSS 7.5 Aug 20, 2021

This SQL injection vulnerability in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary SQL commands via the 'flag' parameter in the order administration component. Attackers can potentially...

CVE-2025-3563

MEDIUM CVSS 4.7 Apr 14, 2025

This critical vulnerability in WuzhiCMS 4.1 allows remote attackers to execute arbitrary code through code injection in the Setting Handler component. Attackers can exploit this by manipulating the 'S...

CVE-2025-0480

MEDIUM CVSS 4.3 Jan 15, 2025

This CVE-2025-0480 vulnerability in wuzhicms 4.1.0 allows attackers to perform server-side request forgery (SSRF) by manipulating sphinxhost/sphinxport parameters in the search admin configuration. At...

CVE-2024-10505

MEDIUM CVSS 6.3 Oct 30, 2024

This critical vulnerability in wuzhicms 4.1.0 allows remote attackers to inject and execute arbitrary code through the add/edit function in block.php. It affects all systems running the vulnerable ver...