Wuzhi Cms Project maintains a content-management system that, despite a narrow product focus, ranks among the more prominent vendors in the vulnerability landscape, indicating significant adoption or deployment density. Its disclosures skew strongly toward critical-severity outcomes and cluster around application-layer input-handling flaws, particularly cross-site scripting and SQL injection vulnerabilities endemic to web-based content platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wuzhi Cms Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15893CRITICAL A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing keywords parameter. | Aug 27, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-17852CRITICAL A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI. | Oct 1, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-15894CRITICAL A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing keyValue parameter. | Aug 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-14515CRITICAL A SQL injection was discovered in WUZHI CMS 4.1.0 that allows remote attackers to inject a malicious SQL statement via the index.php?m=promote&f=index&v=search keywords parameter. | Jul 23, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-16349MEDIUM WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter. | Sep 2, 2018 | 6.1 | 22 | NO | NO |
CVE-2018-16350MEDIUM WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter. | Sep 2, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-14513MEDIUM An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[content] parameter | Jul 23, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-18939MEDIUM An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field. | Nov 5, 2018 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wuzhi Cms Project.
Media articles that mention a CVE ID that affects a product developed by Wuzhi Cms Project — matched by CVE ID, not by vendor name.