Wuzhicms is a modestly scoped web content management system that, despite a narrow product portfolio, maintains prominence in the vulnerability landscape due to its deployment across web properties. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs consistently through web-application weakness classes including cross-site scripting, SQL injection, cross-site request forgery, code injection, and path traversal—a pattern characteristic of input-handling and access-control gaps endemic to CMS platforms. Defenders should treat this vendor's advisories as requiring prioritized review for any deployed instances, particularly those internet-facing; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wuzhicms over time
Signals from CVEs in this vendor scope (58 CVEs).
58 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10312HIGH index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member. | Apr 24, 2018 | 8.8 | 38 | NO | YES |
CVE-2018-9926HIGH An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add. | Apr 10, 2018 | 8.8 | 38 | NO | YES |
CVE-2022-27431CRITICAL Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php. | May 4, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-40670CRITICAL SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file. | Sep 16, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-20572CRITICAL WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893. | Dec 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-17832MEDIUM XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter. | Oct 1, 2018 | 6.1 | 31 | NO | YES |
CVE-2021-41654CRITICAL SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php | Jun 16, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-20122CRITICAL Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php. | Sep 28, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-40674CRITICAL An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php. | Sep 20, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-11722CRITICAL WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded. | Jun 5, 2018 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (58 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wuzhicms.
Media articles that mention a CVE ID that affects a product developed by Wuzhicms — matched by CVE ID, not by vendor name.