VYPR

cszcms

by CSZ CMS

CVEs (35)

  • CVE-2023-41601MedSep 6, 2023
    risk 0.40cvss 6.1epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Database Username or Database Host parameters.

  • CVE-2023-38910MedAug 18, 2023
    risk 0.40cvss 6.1epss 0.00

    CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin.

  • CVE-2021-47738MedDec 23, 2025
    risk 0.35cvss 5.4epss 0.00

    CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message…

  • CVE-2021-47737MedDec 23, 2025
    risk 0.35cvss 5.4epss 0.00

    CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering…

  • CVE-2025-63608MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

  • CVE-2024-27752MedApr 19, 2024
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.

  • CVE-2023-41436MedSep 16, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the Additional Meta Tag parameter in the Pages Content Menu component.

  • CVE-2023-39599MedAug 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter.

  • CVE-2023-38911MedAug 18, 2023
    risk 0.35cvss 5.4epss 0.00

    A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery parameter in the YouTube URL fields.

  • CVE-2020-25392MedJul 9, 2021
    risk 0.35cvss 5.4epss 0.00

    A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Article' field under the 'Article' plugin.

  • CVE-2020-25391MedJul 9, 2021
    risk 0.35cvss 5.4epss 0.00

    A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Pages' field under the 'Pages Content' module.

  • CVE-2021-26776MedMar 11, 2021
    risk 0.35cvss 5.4epss 0.01

    CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.

  • CVE-2021-3224MedMar 10, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.

  • CVE-2023-6302MedNov 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templates of the component File Manager Page. The manipulation leads to permission issues. The attack may be launched remotely. The…

  • CVE-2023-6303LowNov 27, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in CSZCMS 1.3.0. It has been classified as problematic. This affects an unknown part of the file /admin/settings/ of the component Site Settings Page. The manipulation of the argument Additional Meta Tag with the input <animate onbegin=alert(1)…

Page 2 of 2