Vulnerabilities > Wuzhicms > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-21 | CVE-2020-19770 | Cross-site Scripting vulnerability in Wuzhicms Wuzhi CMS 4.1.0 A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie. | 3.5 |
2021-09-21 | CVE-2020-19553 | Cross-site Scripting vulnerability in Wuzhicms Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php. | 3.5 |
2019-03-07 | CVE-2018-17425 | Cross-site Scripting vulnerability in Wuzhicms Wuzhi CMS 4.1.0 WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI. | 3.5 |
2019-03-07 | CVE-2018-17426 | Cross-site Scripting vulnerability in Wuzhicms Wuzhi CMS 4.1.0 WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI. | 3.5 |
2018-11-05 | CVE-2018-18938 | Cross-site Scripting vulnerability in Wuzhicms Wuzhi CMS 4.1.0 An issue was discovered in WUZHI CMS 4.1.0. | 3.5 |
2018-05-29 | CVE-2018-11549 | Cross-site Scripting vulnerability in Wuzhicms Wuzhi CMS 4.1.0 An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring. | 3.5 |
2018-04-26 | CVE-2018-10391 | Cross-site Scripting vulnerability in Wuzhicms Wuzhi CMS 4.1.0 An issue was discovered in WUZHI CMS 4.1.0. | 3.5 |
2018-04-25 | CVE-2018-10367 | Cross-site Scripting vulnerability in Wuzhicms Wuzhi CMS 4.1.0 An issue was discovered in WUZHI CMS 4.1.0. | 3.5 |
2018-04-25 | CVE-2018-10368 | Cross-site Scripting vulnerability in Wuzhicms Wuzhi CMS 4.1.0 An issue was discovered in WUZHI CMS 4.1.0. | 3.5 |
2018-04-24 | CVE-2018-10313 | Cross-site Scripting vulnerability in Wuzhicms Wuzhi CMS 4.1.0 WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI. | 3.5 |