VYPR

Zzcms

by Zzcms

Source repositories

CVEs (119)

  • CVE-2015-7346CriJun 7, 2017
    risk 0.67cvss 9.8epss 0.04

    SQL injection vulnerability in ZCMS 1.1.

  • CVE-2025-22957CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information.

  • CVE-2024-52724CriDec 2, 2024
    risk 0.64cvss 9.8epss 0.01

    ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.

  • CVE-2023-50104CriDec 29, 2023
    risk 0.64cvss 9.8epss 0.01

    ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.

  • CVE-2023-45554CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.

  • CVE-2023-42398CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.

  • CVE-2019-12351CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.

  • CVE-2019-12350CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.

  • CVE-2019-12349CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.

  • CVE-2022-28521CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.02

    ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.

  • CVE-2021-42945CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.

  • CVE-2021-43703CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.02

    An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.

  • CVE-2019-12348CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.

  • CVE-2020-23426CriApr 8, 2021
    risk 0.64cvss 9.8epss 0.04

    zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.

  • CVE-2019-1010153CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.

  • CVE-2019-1010152CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80.

  • CVE-2019-1010150CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php.

  • CVE-2019-1010149CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.

  • CVE-2019-1010148CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.

  • CVE-2019-1010151CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php.

Page 1 of 6