ZeroHour

Vulnerabilities

100 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-50229
Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.

Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.

NVD description · AI analysis pending
9.8<1% PoC
  • jizhicms jizhicms
CVE-2025-50228
Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.

Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.

NVD description · AI analysis pending
9.1<1%
  • jizhicms jizhicms
CVE-2026-29840
JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php.

JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php. The application attempts to sanitize input by filtering tags but fails to recursively remove dangerous event handlers in other HTML tags (such as onerror in tags). This allows an authenticated remote attacker to inject arbitrary web script or HTML via the body parameter in a POST request to /user/release.html.

NVD description · AI analysis pending
5.4<1%
  • jizhicms jizhicms
CVE-2026-3292
A security vulnerability has been detected in jizhiCMS up to 2.5.6.

A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch Interface. The manipulation of the argument data leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1<1% PoC
  • jizhicms jizhicms
CVE-2025-70397
jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

NVD description · AI analysis pending
7.2<1% PoC
  • jizhicms jizhicms
CVE-2020-37117
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files.

jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.

NVD description · AI analysis pending
8.6<1% PoC
  • jizhicms jizhicms
CVE-2025-14012
+2 in the same advisory: …14011 …14013
A vulnerability was determined in JIZHICMS up to 2.5.5.

A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file /index.php/admins/Comment/deleteAll.html of the component Batch Delete Comments. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.0
group max
<1% PoC
  • jizhicms jizhicms
CVE-2025-3563
A vulnerability was found in WuzhiCMS 4.1.

A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachment&f=index&_su=wuzhicms&v=set&submit=1 of the component Setting Handler. The manipulation of the argument Setting leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.1<1% PoC ×2
  • wuzhicms wuzhicms
CVE-2025-2637
+2 in the same advisory: …2638 …2639
A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0.

A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument jifen leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • jizhicms jizhicms
CVE-2025-25916
wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.

wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.

NVD description · AI analysis pending
5.4<1% PoC
  • wuzhicms wuzhicms
CVE-2025-25784
+1 in the same advisory: …25785
An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a

An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • jizhicms jizhicms
CVE-2025-0480
A vulnerability classified as problematic has been found in wuzhicms 4.1.0.

A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC ×2
  • wuzhicms wuzhicms
CVE-2024-10505
A vulnerability was found in wuzhicms 4.1.0.

A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Initially two separate issues were created by the researcher for the different function calls. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3<1% PoC
  • wuzhicms wuzhicms
CVE-2024-34255
jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.

jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.

NVD description · AI analysis pending
6.1<1% PoC
  • jizhicms jizhicms
CVE-2024-33338
Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request.

Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request.

NVD description · AI analysis pending
7.3<1% PoC ×2
  • jizhicms jizhicms
CVE-2024-32206
A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts

A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.

NVD description · AI analysis pending
4.6<1% PoC
  • wuzhicms wuzhicms
CVE-2024-32161
jizhiCMS 2.5 suffers from a File upload vulnerability.

jizhiCMS 2.5 suffers from a File upload vulnerability.

NVD description · AI analysis pending
9.8<1% PoC
  • jizhicms jizhicms
CVE-2024-31008
An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.

An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.

NVD description · AI analysis pending
6.5<1% PoC
  • wuzhicms wuzhicms
CVE-2024-2016
+1 in the same advisory: …2015
A vulnerability, which was classified as critical, was found in ZhiCms 4.0.

A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255270 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
8.81% PoC
  • zhicms zhicms
CVE-2024-0603
A vulnerability classified as critical has been found in ZhiCms up to 4.0.

A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839.

NVD description · AI analysis pending
9.8<1%
  • zhicms zhicms
CVE-2023-52064
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.

Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.

NVD description · AI analysis pending
9.8<1% PoC
  • wuzhicms wuzhicms
CVE-2023-51154
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.

Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.

NVD description · AI analysis pending
9.8<1% PoC
  • jizhicms jizhicms
CVE-2023-50692
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url par

File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.

NVD description · AI analysis pending
8.8<1% PoC
  • jizhicms jizhicms
CVE-2023-46482
SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/da

SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.

NVD description · AI analysis pending
9.81% PoC
  • wuzhicms wuzhicms
CVE-2023-43836
There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information

There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information

NVD description · AI analysis pending
6.5<1% PoC
  • jizhicms jizhicms
CVE-2020-36037
An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.

An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.

NVD description · AI analysis pending
8.81% PoC
  • wuzhicms wuzhicms
CVE-2023-38948
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading

An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.

NVD description · AI analysis pending
7.2<1% PoC
  • jizhicms jizhicms
CVE-2020-20413
+1 in the same advisory: …21325
SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • wuzhicms wuzhicms
CVE-2023-2927
A vulnerability was found in JIZHICMS 2.4.5.

A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file TemplateController.php. The manipulation of the argument webapi leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-230082 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1% PoC
  • jizhicms jizhicms
CVE-2023-31860
Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system.

Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system.

NVD description · AI analysis pending
5.4<1% PoC
  • wuzhicms wuzhicms
CVE-2023-31862
jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS).

jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicious JavaScript scripts by modifying the request package.

NVD description · AI analysis pending
5.4<1% PoC
  • jizhicms jizhicms
CVE-2023-30123
wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings.

wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings.

NVD description · AI analysis pending
5.4<1% PoC
  • wuzhicms wuzhicms
CVE-2023-27235
+1 in the same advisory: …27234
An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute arbitrary code via a crafte

An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute arbitrary code via a crafted phtml file.

NVD description · AI analysis pending
7.2
group max
<1% PoC
  • jizhicms jizhicms
CVE-2021-36484
SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.

SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.

NVD description · AI analysis pending
9.8<1% PoC
  • jizhicms jizhicms
CVE-2022-45278
+2 in the same advisory: …44140 …29334
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.

Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.

NVD description · AI analysis pending
8.8<1% PoC
  • jizhicms jizhicms
CVE-2022-36168
A directory traversal vulnerability was discovered in Wuzhicms 4.1.0.

A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:

NVD description · AI analysis pending
2.7<1% PoC ×2
  • wuzhicms wuzhicms
CVE-2022-36578
+1 in the same advisory: …36577
jizhicms v2.3.1 has SQL injection in the background.

jizhicms v2.3.1 has SQL injection in the background.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • jizhicms jizhicms
CVE-2020-19897
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.

A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • wuzhicms wuzhicms
CVE-2021-41654
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pa

SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php

NVD description · AI analysis pending
9.81% PoC
  • wuzhicms wuzhicms