VYPR

ZKEACMS

by SeriaWei

CVEs (3)

  • CVE-2025-10764MedSep 21, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs of the component Event Action System. Such manipulation of the argument Data leads to server-side request…

  • CVE-2025-10765MedSep 21, 2025
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Suggestions in the library cms-v4.3\wwwroot\Plugins\ZKEACMS.SEOSuggestions\ZKEACMS.SEOSuggestions.dll of the component SEOSuggestions. Performing manipulation…

  • CVE-2025-10766MedSep 21, 2025
    risk 0.28cvss 4.3epss 0.01

    A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file EventViewerController.cs. Executing manipulation of the argument ID can lead to path traversal. It is possible to launch the attack remotely. The exploit has been…