VYPR
Unrated severityNVD Advisory· Published Dec 23, 2025· Updated Apr 7, 2026

CSZ CMS 1.2.7 HTML Injection Vulnerability via Member Dashboard

CVE-2021-47737

Description

CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.