CVE-2026-92380 | WuzhiCMS up to 4.1.0 Remote Image Fetch index.php ckditor::saveRemote source[] server-side request forgery (Issue 221)
A vulnerability, which was classified as critical, has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes server-side request forgery.
This vulnerability is handled as CVE-2026-92380. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More