CVE-2026-94102 | WuzhiCMS up to 4.1.0 Login index.php?m=member&v=Login forward redirect
A vulnerability, which was classified as problematic, has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login of the component Login. This manipulation of the argument forward causes open redirect.
This vulnerability is handled as CVE-2026-94102. The attack can be initiated remotely. Additionally, an exploit exists.
The only sanitization is remove_xss(), an XSS keyword/entity scrubber. The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More