CVE-2020-19157: Wenkucms Project Wenkucms

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.

Affected products

Published 2021-09-15. Last modified 2026-06-17.