CVE-2020-19157: Wenkucms Project Wenkucms
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.
Affected products
- Wenkucms Project Wenkucms: version 3.4 only
Published 2021-09-15. Last modified 2026-06-17.