VYPR

Vendor CVEs

Zzcms

All CVEs

132 total · sorted by risk
  • CVE-2019-9082HigKEVFeb 24, 2019
    risk 0.73cvss 8.8epss 0.97

    ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

  • CVE-2022-23881CriMar 23, 2022
    risk 0.68cvss 9.8epss 0.57

    ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.

  • CVE-2015-7346CriJun 7, 2017
    risk 0.67cvss 9.8epss 0.04

    SQL injection vulnerability in ZCMS 1.1.

  • CVE-2025-22957CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information.

  • CVE-2024-52724CriDec 2, 2024
    risk 0.64cvss 9.8epss 0.01

    ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.

  • CVE-2023-50104CriDec 29, 2023
    risk 0.64cvss 9.8epss 0.01

    ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.

  • CVE-2023-45554CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.

  • CVE-2023-42398CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.

  • CVE-2019-12351CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.

  • CVE-2019-12350CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.

  • CVE-2019-12349CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.

  • CVE-2022-28521CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.02

    ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.

  • CVE-2021-42945CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.

  • CVE-2021-43703CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.02

    An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.

  • CVE-2019-12348CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.

  • CVE-2021-32605CriMay 11, 2021
    risk 0.64cvss 9.8epss 0.04

    zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.

  • CVE-2020-23426CriApr 8, 2021
    risk 0.64cvss 9.8epss 0.04

    zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.

  • CVE-2020-24877CriMar 15, 2021
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.

  • CVE-2020-18717CriFeb 5, 2021
    risk 0.64cvss 9.8epss 0.04

    SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.

  • CVE-2020-20298CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.03

    Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.

  • CVE-2019-17408CriOct 14, 2019
    risk 0.64cvss 9.8epss 0.04

    parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.

  • CVE-2019-16722CriSep 23, 2019
    risk 0.64cvss 9.8epss 0.03

    ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.

  • CVE-2019-1010153CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.

  • CVE-2019-1010152CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80.

  • CVE-2019-1010150CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php.

  • CVE-2019-1010149CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.

  • CVE-2019-1010148CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.

  • CVE-2019-1010151CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php.

  • CVE-2019-10647CriMar 30, 2019
    risk 0.64cvss 9.8epss 0.07

    ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.p…

  • CVE-2018-17412CriMar 7, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.

  • CVE-2018-18792CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.

  • CVE-2018-18791CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.

  • CVE-2018-18789CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.

  • CVE-2018-18787CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.

  • CVE-2018-18786CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.

  • CVE-2018-18785CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.

  • CVE-2018-17136CriSep 17, 2018
    risk 0.64cvss 9.8epss 0.01

    zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.

  • CVE-2018-1000653CriAug 20, 2018
    risk 0.64cvss 9.8epss 0.01

    zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.

  • CVE-2018-14961CriAug 6, 2018
    risk 0.64cvss 9.8epss 0.02

    dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter.

  • CVE-2018-13116CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.01

    /user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.

  • CVE-2018-9309CriApr 5, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.

  • CVE-2018-8967CriMar 24, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.

  • CVE-2024-44817HigSep 4, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.

  • CVE-2023-36162HigJul 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.php.

  • CVE-2019-12358HigJun 17, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie.

  • CVE-2019-12356HigJun 17, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.

  • CVE-2019-12355HigJun 17, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter.

  • CVE-2019-12352HigJun 17, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.

  • CVE-2020-19682HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.

  • CVE-2021-40282HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.

Page 1 of 3