Browse all 6 CVE security advisories affecting WuKongOpenSource. AI-powered Chinese analysis, POCs, and references for each vulnerability.
WuKongOpenSource is an open-source project focused on providing distributed computing and big data processing capabilities. Historically, the project has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, as evidenced by its six recorded CVEs. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities in these categories suggests potential risks for environments where the software is deployed without proper hardening or timely patching. Organizations implementing WuKongOpenSource should prioritize regular security assessments and updates to mitigate these known weaknesses.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-2141 | WuKongOpenSource WukongCRM URL PermissionServiceImpl.java improper authorization — WukongCRMCWE-285 | 6.3 | Medium | 2026-02-08 |
| CVE-2025-8852 | WuKongOpenSource WukongCRM API Response upload information exposure — WukongCRMCWE-209 | 4.3 | Medium | 2025-08-11 |
| CVE-2025-6106 | WuKongOpenSource WukongCRM AdminRoleController.java cross-site request forgery — WukongCRMCWE-352 | 4.3 | Medium | 2025-06-16 |
| CVE-2025-5879 | WuKongOpenSource WukongCRM File Upload AdminSysConfigController.java cross site scripting — WukongCRMCWE-79 | 3.5 | Low | 2025-06-09 |
| CVE-2025-5521 | WuKongOpenSource WukongCRM updataPassword cross-site request forgery — WukongCRMCWE-352 | 4.3 | Medium | 2025-06-03 |
| CVE-2024-6645 | WuKongOpenSource Wukong_nocode AviatorScript ExpressionUtil.java deserialization — Wukong_nocodeCWE-502 | 6.3 | Medium | 2024-07-10 |
This page lists every published CVE security advisory associated with WuKongOpenSource. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.