LOW
Wang.market
CVE published 2026-01-01
CVE-2025-15415
A vulnerability was found in Wangmarket up to version 6.4, affecting the uploadImage function in the /sits/uploadImage.do file. This allows for unrestricted upload of XML files. The vulnerability can be exploited remotely, and an exploit has been publicly disclosed. The vendor did not respond to early disclosure. The vulnerability has a CVSS score of 2 and a severity of LOW. Defenders and administrators s [truncated]