PatchSiren

WuzhiCMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW WuzhiCMS CVE published 2026-09-21

CVE-2026-94102

A security flaw has been identified in WuzhiCMS version 4.1.0 and earlier. The vulnerability is an open redirect issue located in the login functionality of the /index.php?m=member&v=Login file. This issue allows remote attackers to redirect users to arbitrary URLs. The exploit has been made public, and although the vendor was notified, no response was received. The sanitization in place is remove_xss(), [truncated]

MEDIUM WuzhiCMS CVE published 2026-07-13

CVE-2026-15530

A medium-severity vulnerability, CVE-2026-15530, was found in WuzhiCMS up to 4.1.0. This vulnerability affects the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component Attachment API, potentially leading to information disclosure. The vulnerability can be exploited remotely. Users of WuzhiCMS should be aware of this vulnerability and take necessary actions to pro [truncated]