Vendor CVEs
Zzcms
All CVEs
132 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9082 | Hig | 0.73 | 8.8 | 0.97 | KEV | Feb 24, 2019 | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. | |
| CVE-2022-23881 | Cri | 0.68 | 9.8 | 0.57 | Mar 23, 2022 | ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php. | ||
| CVE-2015-7346 | Cri | 0.67 | 9.8 | 0.04 | Jun 7, 2017 | SQL injection vulnerability in ZCMS 1.1. | ||
| CVE-2025-22957 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2025 | A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information. | ||
| CVE-2024-52724 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2024 | ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php. | ||
| CVE-2023-50104 | Cri | 0.64 | 9.8 | 0.01 | Dec 29, 2023 | ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code. | ||
| CVE-2023-45554 | Cri | 0.64 | 9.8 | 0.02 | Oct 25, 2023 | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp. | ||
| CVE-2023-42398 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2023 | An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php. | ||
| CVE-2019-12351 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma. | ||
| CVE-2019-12350 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma. | ||
| CVE-2019-12349 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter. | ||
| CVE-2022-28521 | Cri | 0.64 | 9.8 | 0.02 | Apr 26, 2022 | ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config. | ||
| CVE-2021-42945 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2021 | A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php. | ||
| CVE-2021-43703 | Cri | 0.64 | 9.8 | 0.02 | Dec 9, 2021 | An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console. | ||
| CVE-2019-12348 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2021 | An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter. | ||
| CVE-2021-32605 | Cri | 0.64 | 9.8 | 0.04 | May 11, 2021 | zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block. | ||
| CVE-2020-23426 | Cri | 0.64 | 9.8 | 0.04 | Apr 8, 2021 | zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF. | ||
| CVE-2020-24877 | Cri | 0.64 | 9.8 | 0.02 | Mar 15, 2021 | A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass. | ||
| CVE-2020-18717 | Cri | 0.64 | 9.8 | 0.04 | Feb 5, 2021 | SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php. | ||
| CVE-2020-20298 | Cri | 0.64 | 9.8 | 0.03 | Dec 18, 2020 | Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands. | ||
| CVE-2019-17408 | Cri | 0.64 | 9.8 | 0.04 | Oct 14, 2019 | parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr. | ||
| CVE-2019-16722 | Cri | 0.64 | 9.8 | 0.03 | Sep 23, 2019 | ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation. | ||
| CVE-2019-1010153 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php. | ||
| CVE-2019-1010152 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80. | ||
| CVE-2019-1010150 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php. | ||
| CVE-2019-1010149 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php. | ||
| CVE-2019-1010148 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution. | ||
| CVE-2019-1010151 | Cri | 0.64 | 9.8 | 0.02 | Jul 19, 2019 | zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php. | ||
| CVE-2019-10647 | Cri | 0.64 | 9.8 | 0.07 | Mar 30, 2019 | ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.p… | ||
| CVE-2018-17412 | Cri | 0.64 | 9.8 | 0.02 | Mar 7, 2019 | zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header. | ||
| CVE-2018-18792 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie. | ||
| CVE-2018-18791 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie. | ||
| CVE-2018-18789 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php. | ||
| CVE-2018-18787 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie. | ||
| CVE-2018-18786 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. | ||
| CVE-2018-18785 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php. | ||
| CVE-2018-17136 | Cri | 0.64 | 9.8 | 0.01 | Sep 17, 2018 | zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header. | ||
| CVE-2018-1000653 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2018 | zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx. | ||
| CVE-2018-14961 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2018 | dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter. | ||
| CVE-2018-13116 | Cri | 0.64 | 9.8 | 0.01 | Jul 3, 2018 | /user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table. | ||
| CVE-2018-9309 | Cri | 0.64 | 9.8 | 0.02 | Apr 5, 2018 | An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request. | ||
| CVE-2018-8967 | Cri | 0.64 | 9.8 | 0.02 | Mar 24, 2018 | An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request. | ||
| CVE-2024-44817 | Hig | 0.57 | 8.8 | 0.01 | Sep 4, 2024 | SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component. | ||
| CVE-2023-36162 | Hig | 0.57 | 8.8 | 0.01 | Jul 3, 2023 | Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.php. | ||
| CVE-2019-12358 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie. | ||
| CVE-2019-12356 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter. | ||
| CVE-2019-12355 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter. | ||
| CVE-2019-12352 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie. | ||
| CVE-2020-19682 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2021 | A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php. | ||
| CVE-2021-40282 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2021 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users. |
- risk 0.73cvss 8.8epss 0.97
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
- risk 0.68cvss 9.8epss 0.57
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
- risk 0.67cvss 9.8epss 0.04
SQL injection vulnerability in ZCMS 1.1.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information.
- risk 0.64cvss 9.8epss 0.01
ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.
- risk 0.64cvss 9.8epss 0.01
ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.
- risk 0.64cvss 9.8epss 0.01
An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.
- risk 0.64cvss 9.8epss 0.02
ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.
- risk 0.64cvss 9.8epss 0.01
A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.
- risk 0.64cvss 9.8epss 0.02
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.
- risk 0.64cvss 9.8epss 0.04
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.
- risk 0.64cvss 9.8epss 0.04
zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.
- risk 0.64cvss 9.8epss 0.02
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
- risk 0.64cvss 9.8epss 0.04
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
- risk 0.64cvss 9.8epss 0.03
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
- risk 0.64cvss 9.8epss 0.04
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
- risk 0.64cvss 9.8epss 0.03
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.
- risk 0.64cvss 9.8epss 0.02
zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.
- risk 0.64cvss 9.8epss 0.02
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80.
- risk 0.64cvss 9.8epss 0.02
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php.
- risk 0.64cvss 9.8epss 0.02
zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.
- risk 0.64cvss 9.8epss 0.02
zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.
- risk 0.64cvss 9.8epss 0.02
zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php.
- risk 0.64cvss 9.8epss 0.07
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.p…
- risk 0.64cvss 9.8epss 0.02
zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.
- risk 0.64cvss 9.8epss 0.01
zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.
- risk 0.64cvss 9.8epss 0.01
zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.
- risk 0.64cvss 9.8epss 0.02
dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter.
- risk 0.64cvss 9.8epss 0.01
/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.php.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.
- risk 0.57cvss 8.8epss 0.01
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.
- risk 0.57cvss 8.8epss 0.01
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.
Page 1 of 3