This page aggregates publicly disclosed CVE and security risk information related to wenkucms_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-11138 | A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used. | [email protected] | 2.1 | 4.26% | 2025-09-29 | 2026-04-29 |
| CVE-2020-19157 | Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'. | [email protected] | 6.1 | 0.98% | 2021-09-15 | 2024-11-21 |