Wangmarket
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Wangmarket product.
RSS Feeds for Wangmarket security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Wangmarket products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Wangmarket Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Wangmarket. Last year, in 2025 Wangmarket had 2 security vulnerabilities published. Right now, Wangmarket is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 2 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 2 | 9.80 |
It may take a day or so for new Wangmarket vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Wangmarket Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2025-25770 | Feb 21, 2025 |
Wangmarket CSRF via AgencyUserController (v4.105.0)Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java. |
|
| CVE-2025-25769 | Feb 21, 2025 |
Wangmarket v4.10v5.0 CSRF via UserControllerWangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java. |
|
| CVE-2023-6886 | Dec 17, 2023 |
xnx3 WangMarket 6.1 RP Page: Remote Code InjectionA vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Role Management Page. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248246 is the identifier assigned to this vulnerability. |
|
| CVE-2023-26813 | Apr 28, 2023 |
Wangmarket CMS 4.10 SQLi via TableName in DataDictionaryPluginControllerSQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do. |
|