5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used.
Basic Information
ID
CVE-2025-11138
Source
VulDB
Published
Sep 29, 2025 at 03:02
Affected Product
Vendor
mirweiye
Product
wenkucms
Version
3.0
Affected Versions
mirweiye wenkucms 3.0
mirweiye wenkucms 3.1
mirweiye wenkucms 3.2
mirweiye wenkucms 3.3
mirweiye wenkucms 3.4
mirweiye wenkucms 3.1
mirweiye wenkucms 3.2
mirweiye wenkucms 3.3
mirweiye wenkucms 3.4