Vulnerabilities
100 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-50229 | Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2025-50228 | Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. NVD description · AI analysis pending | 9.1 | <1% |
| — | ||
| CVE-2026-29840 | JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php. JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php. The application attempts to sanitize input by filtering tags but fails to recursively remove dangerous event handlers in other HTML tags (such as onerror in tags). This allows an authenticated remote attacker to inject arbitrary web script or HTML via the body parameter in a POST request to /user/release.html. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2026-3292 | A security vulnerability has been detected in jizhiCMS up to 2.5.6. A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch Interface. The manipulation of the argument data leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-70397 | jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter. jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2020-37117 | jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads. NVD description · AI analysis pending | 8.6 | <1% | PoC |
| — | |
| CVE-2025-14012 | A vulnerability was determined in JIZHICMS up to 2.5.5. A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file /index.php/admins/Comment/deleteAll.html of the component Batch Delete Comments. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.0 group max | <1% | PoC |
| — | |
| CVE-2025-3563 | A vulnerability was found in WuzhiCMS 4.1. A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachment&f=index&_su=wuzhicms&v=set&submit=1 of the component Setting Handler. The manipulation of the argument Setting leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.1 | <1% | PoC ×2 |
| — | |
| CVE-2025-2637 | A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument jifen leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2025-25916 | wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php. wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2025-25784 +1 in the same advisory: …25785 | An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2025-0480 | A vulnerability classified as problematic has been found in wuzhicms 4.1.0. A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | <1% | PoC ×2 |
| — | |
| CVE-2024-10505 | A vulnerability was found in wuzhicms 4.1.0. A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Initially two separate issues were created by the researcher for the different function calls. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2024-34255 | jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function. jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2024-33338 | Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request. Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request. NVD description · AI analysis pending | 7.3 | <1% | PoC ×2 |
| — | |
| CVE-2024-32206 | A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter. NVD description · AI analysis pending | 4.6 | <1% | PoC |
| — | |
| CVE-2024-32161 | jizhiCMS 2.5 suffers from a File upload vulnerability. jizhiCMS 2.5 suffers from a File upload vulnerability. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2024-31008 | An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file. An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-2016 +1 in the same advisory: …2015 | A vulnerability, which was classified as critical, was found in ZhiCms 4.0. A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255270 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2024-0603 | A vulnerability classified as critical has been found in ZhiCms up to 4.0. A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-52064 | Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php. Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-51154 | Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php. Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-50692 | File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url par File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2023-46482 | SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/da SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2023-43836 | There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2020-36037 | An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php. An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2023-38948 | An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2020-20413 +1 in the same advisory: …21325 | SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php. SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2023-2927 | A vulnerability was found in JIZHICMS 2.4.5. A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file TemplateController.php. The manipulation of the argument webapi leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-230082 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-31860 | Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system. Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-31862 | jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicious JavaScript scripts by modifying the request package. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-30123 | wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings. wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-27235 +1 in the same advisory: …27234 | An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute arbitrary code via a crafte An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute arbitrary code via a crafted phtml file. NVD description · AI analysis pending | 7.2 group max | <1% | PoC |
| — | |
| CVE-2021-36484 | SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page. SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-45278 | Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component. Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-36168 | A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php: NVD description · AI analysis pending | 2.7 | <1% | PoC ×2 |
| — | |
| CVE-2022-36578 +1 in the same advisory: …36577 | jizhicms v2.3.1 has SQL injection in the background. jizhicms v2.3.1 has SQL injection in the background. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2020-19897 | A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter. A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2021-41654 | SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pa SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — |