CVE-2026-3957Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This vulnerability affects the function getLikeMovieList of the file source-code/src/main/java/com/moke/wp/wx_weimai/controller/HomeController.java of the component Endpoint. Executing a manipulation of the argument cat can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-03)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 1Mentions · 2026-06-03: 2Technical Details · 2026-06-03: 203-1106-03
Signal classification1 categories
Disclosure
3100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-06-032
Disclosure2
Full discourse3 posts
  • ZAST AI@zast_ai
    Disclosure

    Security note: weimai-wetapp <= 1.0.0 has two verified SQL injection paths. CVE-2026-3956 affects /admin/auser/getAdmins. CVE-2026-3957 affects /home/getLikeMovieList. https://t.co/pGJYaTpZFx

    Post summary

    The note announces two SQL injection vulnerabilities (CVE‑2026‑3956 and CVE‑2026‑3957) affecting endpoints of weimai‑wetapp version ≤1.0.0.

    1101046
    37 followersView on X
  • Geng Yang@geng_zast
    Disclosure

    Same project. Two SQL injection paths. One sits in admin listing logic. The other sits in public recommendation logic. @zast_ai verified CVE-2026-3956 in /admin/auser/getAdmins and CVE-2026-3957 in /home/getLikeMovieList. https://t.co/94kfGvT8TV

    Post summary

    The tweet discloses two verified SQL injection vulnerabilities (CVE-2026-3956 and CVE-2026-3957) in specific project endpoints.

    1100050
    49 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3957 A flaw has been found in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This vulnerability affects the function getLikeMovieList of the file … https://www.cve.org/CVERecord?id=CVE-2026-3957

    Post summary

    The text announces the discovery of CVE‑2026‑3957 in the getLikeMovieList function of xierongwkhd weimai‑wetapp, but provides no details on exploitation, remediation, or technical specifics.

    00000111
    56.7K followersView on X

Explore more