CVE-2026-30404
HIGHwgcloud 3.6.3 Database Connection Test - Server-Side Request Forgery
Title source: manualDescription
The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulnerability. This issue can be exploited to make the server send requests to probe the internal network, remotely download malicious files, and perform other dangerous operations.
References (2)
Core 2
Scores
CVSS v3
7.5
EPSS
0.0025
EPSS Percentile
16.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
wgstart/wgcloud
< 3.6.3
Published
Mar 19, 2026
Tracked Since
Mar 19, 2026