CVE-2026-3956Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This affects the function getAdmins of the file source-code/src/main/java/com/moke/wp/wx_weimai/controller/admin/Admin_AdminUserController.java. Performing a manipulation of the argument keyword results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-03)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 1Mentions · 2026-06-03: 2Technical Details · 2026-06-03: 203-1106-03
Signal classification1 categories
Disclosure
3100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-06-032
Disclosure2
Full discourse3 posts
  • ZAST AI@zast_ai
    Disclosure

    Security note: weimai-wetapp <= 1.0.0 has two verified SQL injection paths. CVE-2026-3956 affects /admin/auser/getAdmins. CVE-2026-3957 affects /home/getLikeMovieList. https://t.co/pGJYaTpZFx

    Post summary

    The note announces two SQL injection vulnerabilities, CVE-2026-3956 and CVE-2026-3957, affecting specific endpoints in weimai-wetapp version 1.0.0.

    1101046
    37 followersView on X
  • Geng Yang@geng_zast
    Disclosure

    Same project. Two SQL injection paths. One sits in admin listing logic. The other sits in public recommendation logic. @zast_ai verified CVE-2026-3956 in /admin/auser/getAdmins and CVE-2026-3957 in /home/getLikeMovieList. https://t.co/94kfGvT8TV

    Post summary

    The tweet announces the discovery of two SQL injection vulnerabilities in a project, detailing the affected endpoints and CVE numbers, but does not provide PoC code, exploit tools, active exploitation evidence, or patch information.

    1100050
    49 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3956 A vulnerability was detected in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This affects the function getAdmins of the file source-code/sr… https://www.cve.org/CVERecord?id=CVE-2026-3956

    Post summary

    The text announces the detection of CVE‑2026‑3956, indicating it affects the getAdmins function in a particular software version and directs readers to the official CVE record for more information.

    00000132
    56.7K followersView on X

Explore more