Wuzhicms · Wuzhi Cms · CVE-2026-15530
**Name of the Vulnerable Software and Affected Versions**
WuzhiCMS versions prior to 4.1.1
**Description**
A flaw in the Attachment API component allows remote information disclosure. The issue resides in the `config/listimage` function within the '/index.php?m=attachment&f=index&v=upload' endpoint.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the '/index.php?m=attachment&f=index&v=upload' endpoint or disable the `config/listimage` function.