Review reviewHigh
CVE-2025-55849
weiphp
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
- CVSS
- 8.4
- EPSS
- 0.18% 8.21% percentile
- CISA KEV
- Not listed
- Published
- 2025.09.09
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
The CVSS severity warrants an early asset and exposure review.
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
Confirm exposure before applying a vendor-supported change.
Confirm that weiphp and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.