A remote attacker can escalate privileges in Wgcloud 3.6.4 via the content parameter, which is directly concatenated to the ProcessBuilder. This vulnerability has a CVSS score of 4.3, indicating a medium severity vulnerability. The CVE record was published on 2026-08-26T21:16:38.463Z and has not been modified since then. Limited source detail is available; further review is recommended to confirm affected [truncated]
A SQL injection vulnerability exists in Wgcloud version 3.6.4. This vulnerability allows a remote attacker to escalate privileges via the PortInfoMapper.xml file. The Common Vulnerabilities and Exposures (CVE) score for this vulnerability is 9.8, indicating a critical severity level. The vulnerability is caused by a lack of proper input validation in the PortInfoMapper.xml file, allowing an attacker to in [truncated]