← Back

Weiphp

weiphp

Vendor: Weiphp • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Weiphp
1Weiphp
Jul 5, 2026
Sep 8, 2025
N/A· v4
8.4 HIGH· v3
N/A· v2
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
1Weiphp
1Weiphp
Jun 17, 2026
Jun 26, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework by Shenzhen Yuanmengyun Technology Co., Ltd. The flaw occurs in the picUrl parameter of the /public...Show more
A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework by Shenzhen Yuanmengyun Technology Co., Ltd. The flaw occurs in the picUrl parameter of the /public/index.php/material/Material/_download_imgage endpoint, where insufficient input validation allows unauthenticated remote attackers to perform directory traversal via crafted POST requests. This enables arbitrary file read on the server, potentially exposing sensitive information such as configuration files and source code. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.Show less
1Weiphp
1Weiphp
Jun 17, 2026
Dec 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
1Weiphp
1Weiphp
Jun 17, 2026
Dec 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WeiPHP 5.0 does not properly restrict access to pages, related to using POST.