CVE-2026-92380: WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery
A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
WuzhiCMS versions up to and including 4.1.0 are affected in the Remote Image Fetch functionality handled by ckditor::saveRemote in coreframe/app/attachment/index.php.
What access does an attacker need to exploit this issue?
The attack can be initiated remotely and does not require privileges or user interaction, according to the supplied vector. Exploitation involves manipulating the source[] argument.
Is public exploitation a concern?
Yes. An exploit has been published and may be used, so exposed affected installations should be treated as having practical exploitation risk.
Is a vendor fix available?
The provided information does not identify a fix. It states that the project was informed through an issue report but had not responded at the time of publication.