Zzcms
by Zzcms
Source repositories
CVEs (119)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-13171 | Med | 0.41 | 6.3 | 0.00 | Nov 14, 2025 | A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | ||
| CVE-2024-10293 | Med | 0.41 | 6.3 | 0.01 | Oct 23, 2024 | A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/class/functions.php. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack… | ||
| CVE-2024-10292 | Med | 0.41 | 6.3 | 0.01 | Oct 23, 2024 | A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be initiated remotely. The… | ||
| CVE-2024-10291 | Med | 0.41 | 6.3 | 0.00 | Oct 23, 2024 | A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_DoExecSQL/Ebak_DotranExecutSQL of the file 3/Ebak5.1/upload/phome.php. The manipulation of the argument phome leads to sql injection. The attack can be initiated… | ||
| CVE-2023-5263 | Med | 0.41 | 6.3 | 0.01 | Sep 29, 2023 | A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of the file /admin/save.php of the component Database Backup File Handler. The manipulation leads to permission issues. The attack may be launched remotely. The… | ||
| CVE-2024-44820 | Med | 0.40 | 6.1 | 0.00 | Sep 4, 2024 | A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed… | ||
| CVE-2024-44819 | Med | 0.40 | 6.1 | 0.00 | Sep 4, 2024 | Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component. | ||
| CVE-2023-45909 | Med | 0.40 | 6.1 | 0.00 | Oct 18, 2023 | zzzcms v2.2.0 was discovered to contain an open redirect vulnerability. | ||
| CVE-2020-19042 | Med | 0.40 | 6.1 | 0.01 | Dec 13, 2021 | Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php. | ||
| CVE-2018-17413 | Med | 0.40 | 6.1 | 0.01 | Mar 7, 2019 | XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter. | ||
| CVE-2024-44818 | Med | 0.35 | 5.4 | 0.00 | Sep 4, 2024 | Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component. | ||
| CVE-2024-7924 | Med | 0.35 | 5.3 | 0.01 | Aug 19, 2024 | A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the… | ||
| CVE-2024-43006 | Med | 0.35 | 5.4 | 0.00 | Aug 16, 2024 | A stored cross-site scripting (XSS) vulnerability exists in ZZCMS2023 in the ask/show.php file at line 21. An attacker can exploit this vulnerability by sending a specially crafted POST request to /user/ask_edit.php?action=add, which includes malicious JavaScript code in the… | ||
| CVE-2022-44361 | Med | 0.35 | 5.4 | 0.00 | Dec 7, 2022 | An issue was discovered in ZZCMS 2022. There is a cross-site scripting (XSS) vulnerability in admin/ad_list.php. | ||
| CVE-2022-40444 | Med | 0.35 | 5.3 | 0.01 | Sep 22, 2022 | ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server. | ||
| CVE-2022-40443 | Med | 0.35 | 5.3 | 0.02 | Sep 22, 2022 | An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php. | ||
| CVE-2022-28522 | Med | 0.35 | 5.4 | 0.01 | Apr 26, 2022 | ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add. | ||
| CVE-2021-45286 | Med | 0.35 | 5.3 | 0.02 | Feb 9, 2022 | Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php. | ||
| CVE-2020-19683 | Med | 0.35 | 5.4 | 0.01 | Dec 9, 2021 | A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php. | ||
| CVE-2020-35973 | Med | 0.35 | 5.4 | 0.01 | Jun 3, 2021 | An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php. |
- risk 0.41cvss 6.3epss 0.00
A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/class/functions.php. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be initiated remotely. The…
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_DoExecSQL/Ebak_DotranExecutSQL of the file 3/Ebak5.1/upload/phome.php. The manipulation of the argument phome leads to sql injection. The attack can be initiated…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of the file /admin/save.php of the component Database Backup File Handler. The manipulation leads to permission issues. The attack may be launched remotely. The…
- risk 0.40cvss 6.1epss 0.00
A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed…
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component.
- risk 0.40cvss 6.1epss 0.00
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php.
- risk 0.40cvss 6.1epss 0.01
XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter.
- risk 0.35cvss 5.4epss 0.00
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component.
- risk 0.35cvss 5.3epss 0.01
A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the…
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability exists in ZZCMS2023 in the ask/show.php file at line 21. An attacker can exploit this vulnerability by sending a specially crafted POST request to /user/ask_edit.php?action=add, which includes malicious JavaScript code in the…
- risk 0.35cvss 5.4epss 0.00
An issue was discovered in ZZCMS 2022. There is a cross-site scripting (XSS) vulnerability in admin/ad_list.php.
- risk 0.35cvss 5.3epss 0.01
ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.
- risk 0.35cvss 5.3epss 0.02
An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.
- risk 0.35cvss 5.4epss 0.01
ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add.
- risk 0.35cvss 5.3epss 0.02
Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.
- risk 0.35cvss 5.4epss 0.01
A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.
Page 5 of 6