WCMS是Vedegis个人开发者的一套内容管理系统(CMS)。 WCMS 11版本存在注入漏洞,该漏洞源于文件app/controllers/AnonymousController.php中参数mobile_phone操作导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | WCMS | 11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-3799 | 7.3 HIGH | WCMS AnonymousController.php sql injection |
| CVE-2025-3798 | 4.7 MEDIUM | WCMS Advertisement Image AdvadminController.php sub unrestricted upload |
| CVE-2025-3797 | 4.7 MEDIUM | SeaCMS admin_topic.php sql injection |
No comments yet