Lucene search

K

Zzcms Security Vulnerabilities

cve
cve

CVE-2023-50104

ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary...

9.8CVSS

9.8AI Score

0.001EPSS

2023-12-29 12:15 AM
18
cve
cve

CVE-2023-42398

An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in...

9.8CVSS

9.4AI Score

0.003EPSS

2023-09-15 05:15 PM
64
cve
cve

CVE-2023-36162

Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in...

8.8CVSS

8.7AI Score

0.001EPSS

2023-07-03 09:15 PM
96
cve
cve

CVE-2022-44361

An issue was discovered in ZZCMS 2022. There is a cross-site scripting (XSS) vulnerability in...

5.4CVSS

5.3AI Score

0.001EPSS

2022-12-07 05:15 PM
24
cve
cve

CVE-2018-1000653

zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in...

9.8CVSS

9.7AI Score

0.002EPSS

2022-10-03 04:21 PM
20
cve
cve

CVE-2022-40447

ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at...

7.2CVSS

7.2AI Score

0.001EPSS

2022-09-22 02:15 PM
20
6
cve
cve

CVE-2022-40444

ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP?...

5.3CVSS

5.2AI Score

0.001EPSS

2022-09-22 02:15 PM
19
6
cve
cve

CVE-2022-40443

An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to...

5.3CVSS

4.9AI Score

0.001EPSS

2022-09-22 02:15 PM
16
6
cve
cve

CVE-2022-40446

ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component...

7.2CVSS

7.2AI Score

0.001EPSS

2022-09-22 02:15 PM
18
6
cve
cve

CVE-2019-12352

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid...

8.8CVSS

8.9AI Score

0.001EPSS

2022-06-17 01:15 PM
26
5
cve
cve

CVE-2019-12354

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id...

7.2CVSS

7.2AI Score

0.001EPSS

2022-06-17 01:15 PM
25
5
cve
cve

CVE-2019-12355

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id...

8.8CVSS

8.9AI Score

0.001EPSS

2022-06-17 01:15 PM
22
5
cve
cve

CVE-2019-12357

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id...

7.2CVSS

7.2AI Score

0.001EPSS

2022-06-17 01:15 PM
31
5
cve
cve

CVE-2019-12358

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid...

8.8CVSS

8.9AI Score

0.001EPSS

2022-06-17 01:15 PM
24
3
cve
cve

CVE-2019-12359

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id...

7.2CVSS

7.2AI Score

0.001EPSS

2022-06-17 01:15 PM
32
5
cve
cve

CVE-2019-12353

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id...

7.2CVSS

7.2AI Score

0.001EPSS

2022-06-17 01:15 PM
24
7
cve
cve

CVE-2019-12356

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id...

8.8CVSS

8.9AI Score

0.001EPSS

2022-06-17 01:15 PM
23
5
cve
cve

CVE-2019-12351

An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing...

9.8CVSS

9.8AI Score

0.002EPSS

2022-06-02 02:15 PM
17
8
cve
cve

CVE-2019-12349

An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id...

9.8CVSS

9.8AI Score

0.002EPSS

2022-06-02 02:15 PM
26
5
cve
cve

CVE-2019-12350

An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing...

9.8CVSS

9.8AI Score

0.002EPSS

2022-06-02 02:15 PM
22
8
cve
cve

CVE-2021-46437

An issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in...

4.8CVSS

4.9AI Score

0.001EPSS

2022-04-08 11:15 AM
54
cve
cve

CVE-2021-46436

An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in...

7.2CVSS

7.2AI Score

0.001EPSS

2022-04-08 11:15 AM
62
cve
cve

CVE-2021-45347

An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any...

7.5CVSS

7.6AI Score

0.001EPSS

2022-02-14 07:15 PM
51
cve
cve

CVE-2021-45286

Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3)...

5.3CVSS

5.3AI Score

0.001EPSS

2022-02-09 08:15 PM
33
cve
cve

CVE-2021-42945

A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in...

9.8CVSS

9.8AI Score

0.002EPSS

2021-12-15 07:15 AM
24
3
cve
cve

CVE-2020-19042

Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in...

6.1CVSS

5.7AI Score

0.001EPSS

2021-12-13 09:15 PM
22
cve
cve

CVE-2021-43703

An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator...

9.8CVSS

9.4AI Score

0.004EPSS

2021-12-09 05:15 PM
18
cve
cve

CVE-2021-40282

An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary...

8.8CVSS

9.1AI Score

0.001EPSS

2021-12-09 05:15 PM
18
cve
cve

CVE-2021-40281

An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary...

8.8CVSS

9.1AI Score

0.001EPSS

2021-12-09 05:15 PM
21
cve
cve

CVE-2021-40279

An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in...

7.2CVSS

7.4AI Score

0.001EPSS

2021-12-09 04:15 PM
16
cve
cve

CVE-2021-40280

An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in...

7.2CVSS

7.4AI Score

0.001EPSS

2021-12-09 04:15 PM
24
cve
cve

CVE-2020-19957

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php...

7.5CVSS

7.7AI Score

0.002EPSS

2021-10-14 03:15 PM
20
cve
cve

CVE-2020-19960

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page...

7.5CVSS

7.8AI Score

0.002EPSS

2021-10-14 03:15 PM
24
cve
cve

CVE-2020-19961

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component...

7.5CVSS

7.7AI Score

0.002EPSS

2021-10-14 03:15 PM
20
cve
cve

CVE-2020-19959

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page...

7.5CVSS

7.8AI Score

0.002EPSS

2021-10-14 03:15 PM
21
cve
cve

CVE-2020-19822

A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title"...

7.2CVSS

7.6AI Score

0.004EPSS

2021-08-26 03:15 AM
37
4
cve
cve

CVE-2020-35973

An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via...

5.4CVSS

5.4AI Score

0.001EPSS

2021-06-03 09:15 PM
35
5
cve
cve

CVE-2019-12348

An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST...

9.8CVSS

9.9AI Score

0.002EPSS

2021-05-24 04:15 PM
23
cve
cve

CVE-2020-21342

Insecure permissions issue in zzcms 201910 via the reset any user password in...

7.5CVSS

7.6AI Score

0.001EPSS

2021-05-13 03:15 PM
11
2
cve
cve

CVE-2020-23426

zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as...

9.8CVSS

9.4AI Score

0.003EPSS

2021-04-08 03:15 PM
14
cve
cve

CVE-2020-23630

A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie...

8.8CVSS

8.9AI Score

0.002EPSS

2021-01-11 03:15 PM
19
1
cve
cve

CVE-2020-20285

There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via...

5.4CVSS

5.3AI Score

0.002EPSS

2020-12-18 07:15 PM
24
1
cve
cve

CVE-2019-1010149

zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is:...

9.8CVSS

9.4AI Score

0.009EPSS

2019-07-23 02:15 PM
27
cve
cve

CVE-2019-1010152

zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line...

9.8CVSS

9.4AI Score

0.009EPSS

2019-07-23 02:15 PM
26
cve
cve

CVE-2019-1010150

zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is:...

9.8CVSS

9.4AI Score

0.009EPSS

2019-07-23 02:15 PM
23
cve
cve

CVE-2019-1010153

zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is:...

9.8CVSS

9.6AI Score

0.002EPSS

2019-07-23 02:15 PM
18
cve
cve

CVE-2019-1010148

zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code...

9.8CVSS

9.6AI Score

0.003EPSS

2019-07-23 02:15 PM
22
cve
cve

CVE-2018-17416

A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid...

7.2CVSS

7.3AI Score

0.001EPSS

2019-03-07 11:29 PM
21
cve
cve

CVE-2018-17415

zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id...

8.8CVSS

8.9AI Score

0.001EPSS

2019-03-07 11:29 PM
23
cve
cve

CVE-2018-17412

zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP...

9.8CVSS

9.7AI Score

0.002EPSS

2019-03-07 11:29 PM
18
Total number of security vulnerabilities80