← Back

Wdja

wdja

5 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Wdja Cms
wdja_cms
Wdja
wdja

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wdja
1Wdja
Jun 17, 2026
May 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.
1Wdja
1Wdja Cms
Jun 17, 2026
Nov 3, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.
1Wdja
1Wdja Cms
Jun 17, 2026
Oct 6, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a crafted URL.
1Wdja
1Wdja Cms
Jun 17, 2026
Oct 6, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
WDJA CMS v1.5.2 contains an arbitrary file deletion vulnerability in the component admin/cache/manage.php.
1Wdja
1Wdja Cms
Jun 17, 2026
Jan 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via the tongji parameter.