wuzhicms CVE Vulnerabilities & Metrics

Focus on wuzhicms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About wuzhicms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with wuzhicms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total wuzhicms CVEs: 53
Earliest CVE date: 10 Apr 2018, 06:29 UTC
Latest CVE date: 30 Oct 2024, 02:15 UTC

Latest CVE reference: CVE-2024-10505

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -85.71%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -85.71%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical wuzhicms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.55

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 19
4.0-6.9 25
7.0-8.9 9
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS wuzhicms CVEs

These are the five CVEs with the highest CVSS scores for wuzhicms, sorted by severity first and recency.

All CVEs for wuzhicms

CVE-2024-10505 wuzhicms vulnerability CVSS: 6.5 30 Oct 2024, 02:15 UTC

A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Initially two separate issues were created by the researcher for the different function calls. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-52064 wuzhicms vulnerability CVSS: 0 10 Jan 2024, 21:15 UTC

Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.

CVE-2023-46482 wuzhicms vulnerability CVSS: 0 01 Nov 2023, 19:15 UTC

SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.

CVE-2020-36037 wuzhicms vulnerability CVSS: 0 11 Aug 2023, 14:15 UTC

An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.

CVE-2020-21325 wuzhicms vulnerability CVSS: 0 20 Jun 2023, 15:15 UTC

An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.

CVE-2020-20413 wuzhicms vulnerability CVSS: 0 20 Jun 2023, 15:15 UTC

SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

CVE-2023-31860 wuzhicms vulnerability CVSS: 0 23 May 2023, 20:15 UTC

Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system.

CVE-2023-30123 wuzhicms vulnerability CVSS: 0 28 Apr 2023, 14:15 UTC

wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings.

CVE-2022-36168 wuzhicms vulnerability CVSS: 0 26 Aug 2022, 00:15 UTC

A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:

CVE-2020-19897 wuzhicms vulnerability CVSS: 4.3 28 Jun 2022, 22:15 UTC

A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.

CVE-2021-41654 wuzhicms vulnerability CVSS: 7.5 16 Jun 2022, 12:15 UTC

SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php

CVE-2022-27431 wuzhicms vulnerability CVSS: 7.5 04 May 2022, 03:15 UTC

Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.

CVE-2020-19770 wuzhicms vulnerability CVSS: 3.5 21 Dec 2021, 18:15 UTC

A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.

CVE-2020-28145 wuzhicms vulnerability CVSS: 5.0 12 Oct 2021, 11:15 UTC

Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.

CVE-2020-20124 wuzhicms vulnerability CVSS: 6.5 28 Sep 2021, 23:15 UTC

Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.

CVE-2020-20122 wuzhicms vulnerability CVSS: 7.5 28 Sep 2021, 23:15 UTC

Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.

CVE-2020-24930 wuzhicms vulnerability CVSS: 5.5 27 Sep 2021, 21:15 UTC

Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five fingers CMS backend in***.php file has arbitrary file deletion vulnerability. Attackers can use vulnerabilities to delete arbitrary files.

CVE-2020-19553 wuzhicms vulnerability CVSS: 3.5 21 Sep 2021, 19:15 UTC

Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php.

CVE-2020-19551 wuzhicms vulnerability CVSS: 6.5 21 Sep 2021, 19:15 UTC

Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.

CVE-2020-19915 wuzhicms vulnerability CVSS: 4.3 20 Sep 2021, 19:15 UTC

Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.

CVE-2021-40674 wuzhicms vulnerability CVSS: 7.5 20 Sep 2021, 15:15 UTC

An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.

CVE-2021-40670 wuzhicms vulnerability CVSS: 7.5 16 Sep 2021, 19:15 UTC

SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file.

CVE-2021-40669 wuzhicms vulnerability CVSS: 7.5 16 Sep 2021, 19:15 UTC

SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file.

CVE-2020-18877 wuzhicms vulnerability CVSS: 5.0 20 Aug 2021, 14:15 UTC

SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.

CVE-2020-18654 wuzhicms vulnerability CVSS: 4.3 22 Jun 2021, 16:15 UTC

Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".

CVE-2020-21590 wuzhicms vulnerability CVSS: 4.0 02 Apr 2021, 20:15 UTC

Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter.

CVE-2018-17426 wuzhicms vulnerability CVSS: 3.5 07 Mar 2019, 23:29 UTC

WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.

CVE-2018-17425 wuzhicms vulnerability CVSS: 3.5 07 Mar 2019, 23:29 UTC

WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.

CVE-2019-9110 wuzhicms vulnerability CVSS: 4.3 25 Feb 2019, 01:29 UTC

XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.

CVE-2019-9109 wuzhicms vulnerability CVSS: 4.3 25 Feb 2019, 01:29 UTC

XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.php.

CVE-2019-9108 wuzhicms vulnerability CVSS: 4.3 25 Feb 2019, 01:29 UTC

XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php.

CVE-2019-9107 wuzhicms vulnerability CVSS: 4.3 25 Feb 2019, 01:29 UTC

XSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imagecut.php.

CVE-2018-20572 wuzhicms vulnerability CVSS: 7.5 28 Dec 2018, 16:29 UTC

WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.

CVE-2018-18938 wuzhicms vulnerability CVSS: 3.5 05 Nov 2018, 09:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.

CVE-2018-18712 wuzhicms vulnerability CVSS: 6.8 29 Oct 2018, 12:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.

CVE-2018-18711 wuzhicms vulnerability CVSS: 6.8 29 Oct 2018, 12:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.

CVE-2018-17832 wuzhicms vulnerability CVSS: 4.3 01 Oct 2018, 08:29 UTC

XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.

CVE-2018-14512 wuzhicms vulnerability CVSS: 4.3 23 Jul 2018, 08:29 UTC

An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.

CVE-2018-14472 wuzhicms vulnerability CVSS: 6.5 20 Jul 2018, 16:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.

CVE-2018-11722 wuzhicms vulnerability CVSS: 7.5 05 Jun 2018, 12:29 UTC

WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.

CVE-2018-11549 wuzhicms vulnerability CVSS: 3.5 29 May 2018, 21:29 UTC

An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.

CVE-2018-11528 wuzhicms vulnerability CVSS: 7.5 29 May 2018, 07:29 UTC

WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.

CVE-2018-11493 wuzhicms vulnerability CVSS: 6.8 26 May 2018, 18:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.

CVE-2018-10391 wuzhicms vulnerability CVSS: 3.5 26 Apr 2018, 05:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.

CVE-2018-10368 wuzhicms vulnerability CVSS: 3.5 25 Apr 2018, 09:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.

CVE-2018-10367 wuzhicms vulnerability CVSS: 3.5 25 Apr 2018, 09:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.

CVE-2018-10313 wuzhicms vulnerability CVSS: 3.5 24 Apr 2018, 02:29 UTC

WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.

CVE-2018-10312 wuzhicms vulnerability CVSS: 6.8 24 Apr 2018, 02:29 UTC

index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.

CVE-2018-10311 wuzhicms vulnerability CVSS: 4.3 24 Apr 2018, 02:29 UTC

A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.

CVE-2018-10248 wuzhicms vulnerability CVSS: 5.8 20 Apr 2018, 17:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.

CVE-2018-10221 wuzhicms vulnerability CVSS: 3.5 19 Apr 2018, 08:29 UTC

An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lower than the administrator) logs in, he can add a new TAGS with the XSS payload.

CVE-2018-9927 wuzhicms vulnerability CVSS: 6.8 10 Apr 2018, 06:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.

CVE-2018-9926 wuzhicms vulnerability CVSS: 6.8 10 Apr 2018, 06:29 UTC

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.