Zzcms
Products
5- 119 CVEs
- 14 CVEs
- 6 CVEs
- 1 CVE
- 1 CVE
Recent CVEs
132| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9082 | Hig | 0.73 | 8.8 | 0.97 | KEV | Feb 24, 2019 | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. | |
| CVE-2022-23881 | Cri | 0.68 | 9.8 | 0.57 | Mar 23, 2022 | ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php. | ||
| CVE-2015-7346 | Cri | 0.67 | 9.8 | 0.04 | Jun 7, 2017 | SQL injection vulnerability in ZCMS 1.1. | ||
| CVE-2025-22957 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2025 | A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information. | ||
| CVE-2024-52724 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2024 | ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php. | ||
| CVE-2023-50104 | Cri | 0.64 | 9.8 | 0.01 | Dec 29, 2023 | ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code. | ||
| CVE-2023-45554 | Cri | 0.64 | 9.8 | 0.02 | Oct 25, 2023 | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp. | ||
| CVE-2023-42398 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2023 | An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php. | ||
| CVE-2019-12351 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma. | ||
| CVE-2019-12350 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma. | ||
| CVE-2019-12349 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter. | ||
| CVE-2022-28521 | Cri | 0.64 | 9.8 | 0.02 | Apr 26, 2022 | ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config. | ||
| CVE-2021-42945 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2021 | A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php. | ||
| CVE-2021-43703 | Cri | 0.64 | 9.8 | 0.02 | Dec 9, 2021 | An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console. | ||
| CVE-2019-12348 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2021 | An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter. | ||
| CVE-2021-32605 | Cri | 0.64 | 9.8 | 0.04 | May 11, 2021 | zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block. | ||
| CVE-2020-23426 | Cri | 0.64 | 9.8 | 0.04 | Apr 8, 2021 | zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF. | ||
| CVE-2020-24877 | Cri | 0.64 | 9.8 | 0.02 | Mar 15, 2021 | A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass. | ||
| CVE-2020-18717 | Cri | 0.64 | 9.8 | 0.04 | Feb 5, 2021 | SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php. | ||
| CVE-2020-20298 | Cri | 0.64 | 9.8 | 0.03 | Dec 18, 2020 | Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands. |
- risk 0.73cvss 8.8epss 0.97
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
- risk 0.68cvss 9.8epss 0.57
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
- risk 0.67cvss 9.8epss 0.04
SQL injection vulnerability in ZCMS 1.1.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information.
- risk 0.64cvss 9.8epss 0.01
ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.
- risk 0.64cvss 9.8epss 0.01
ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.
- risk 0.64cvss 9.8epss 0.01
An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.
- risk 0.64cvss 9.8epss 0.02
ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.
- risk 0.64cvss 9.8epss 0.01
A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.
- risk 0.64cvss 9.8epss 0.02
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.
- risk 0.64cvss 9.8epss 0.04
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.
- risk 0.64cvss 9.8epss 0.04
zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.
- risk 0.64cvss 9.8epss 0.02
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
- risk 0.64cvss 9.8epss 0.04
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
- risk 0.64cvss 9.8epss 0.03
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.