Weiphp is a web application framework with a compact vulnerability footprint centered on its core product, where the durable signal reflects application-layer input-handling weaknesses including SQL injection and path traversal. These exposure patterns are characteristic of web framework implementations and reflect the complexity of safely handling user input and file-system access in such systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weiphp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-20300CRITICAL SQL injection vulnerability in the wp_where function in WeiPHP 5.0. | Dec 18, 2020 | 9.8 | 44 | NO | YES |
CVE-2025-34045HIGH A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework by Shenzhen Yuanmengyun Technology Co., Ltd. The flaw occur | Jun 26, 2025 | 7.5 | 38 | NO | YES |
CVE-2025-55849HIGH WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee | Sep 8, 2025 | 8.4 | 29 | NO | NO |
CVE-2020-20299HIGH WeiPHP 5.0 does not properly restrict access to pages, related to using POST. | Dec 18, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weiphp.
Media articles that mention a CVE ID that affects a product developed by Weiphp — matched by CVE ID, not by vendor name.