Wang.Market develops a small e-commerce content management platform that skews toward serious severity outcomes across its disclosures, with vulnerabilities centered on the WangMarket CMS product. The recurring weakness classes—code injection, cross-site scripting, CSRF, access control bypass, and SQL injection—are characteristic of web application input handling and session management and reflect the attack surface of a publicly facing commerce platform. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wang.Market over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26813CRITICAL SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitr | Apr 28, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-6886CRITICAL A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Role Management Page. The man | Dec 17, 2023 | 9.8 | 26 | NO | NO |
CVE-2025-25769HIGH Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java. | Feb 21, 2025 | 8.0 | 23 | NO | NO |
CVE-2025-15416MEDIUM A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of the component Add Global Variable Handler. The manipulation | Jan 1, 2026 | 5.4 | 20 | NO | NO |
CVE-2025-15415MEDIUM A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the component XML File Handler. Th | Jan 1, 2026 | 5.4 | 20 | NO | NO |
CVE-2025-25770MEDIUM Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java. | Feb 21, 2025 | 6.8 | 20 | NO | NO |
CVE-2025-15452MEDIUM A weakness has been identified in xnx3 wangmarket up to 4.9. This affects the function variableList of the file /admin/system/variableList.do of the component Backend Variable Sear | Jan 5, 2026 | 4.8 | 19 | NO | NO |
CVE-2025-15451MEDIUM A security flaw has been discovered in xnx3 wangmarket up to 4.9. Affected by this issue is some unknown functionality of the file /admin/system/variableSave.do of the component Sy | Jan 5, 2026 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wang.Market.
Media articles that mention a CVE ID that affects a product developed by Wang.Market — matched by CVE ID, not by vendor name.