VYPR

Remote Image Fetch

by WuzhiCMS

CVEs (1)

  • CVE-2026-92380HigSep 16, 2026
    risk 0.47cvss 7.3epss

    A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes server-side request forgery. The attack…