VYPR

Vendor CVEs

Zzcms

All CVEs

132 total · sorted by risk
  • CVE-2021-40281HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.

  • CVE-2020-23630HigJan 11, 2021
    risk 0.57cvss 8.8epss 0.01

    A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).

  • CVE-2018-17415HigMar 7, 2019
    risk 0.57cvss 8.8epss 0.01

    zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter.

  • CVE-2018-17414HigMar 7, 2019
    risk 0.57cvss 8.8epss 0.01

    zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter.

  • CVE-2019-9182HigFeb 26, 2019
    risk 0.57cvss 8.8epss 0.01

    There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter.

  • CVE-2018-14963HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.01

    zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.

  • CVE-2019-9041HigFeb 23, 2019
    risk 0.52cvss 7.2epss 0.31

    An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.

  • CVE-2023-45555HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.01

    File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.

  • CVE-2021-45347HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.

  • CVE-2020-19961HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.

  • CVE-2020-19960HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.

  • CVE-2020-19959HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.

  • CVE-2020-19957HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.

  • CVE-2020-21342HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.

  • CVE-2019-16720HigSep 23, 2019
    risk 0.49cvss 7.5epss 0.01

    ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.

  • CVE-2019-8411HigFeb 17, 2019
    risk 0.49cvss 7.5epss 0.03

    admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=../ directory traversal.

  • CVE-2018-20127HigDec 13, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds.

  • CVE-2018-16344HigSep 2, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-13056HigJul 2, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_main table and then making an img add request. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-9331HigApr 7, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-8969HigMar 24, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-8968HigMar 24, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-8966HigMar 24, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.

  • CVE-2018-8965HigMar 24, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2025-0565HigJan 19, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to…

  • CVE-2024-7927HigAug 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the argument skin[] leads to path traversal. The attack can be launched remotely. The…

  • CVE-2024-7926HigAug 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2022-40447HigSep 22, 2022
    risk 0.47cvss 7.2epss 0.01

    ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.

  • CVE-2022-40446HigSep 22, 2022
    risk 0.47cvss 7.2epss 0.01

    ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.

  • CVE-2019-12359HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12357HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12354HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12353HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.

  • CVE-2021-46436HigApr 8, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.

  • CVE-2021-40280HigDec 9, 2021
    risk 0.47cvss 7.2epss 0.01

    An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.

  • CVE-2021-40279HigDec 9, 2021
    risk 0.47cvss 7.2epss 0.01

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.

  • CVE-2020-19822HigAug 26, 2021
    risk 0.47cvss 7.2epss 0.03

    A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.

  • CVE-2018-17416HigMar 7, 2019
    risk 0.47cvss 7.2epss 0.01

    A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter.

  • CVE-2018-18790HigOct 29, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.)

  • CVE-2018-18788HigOct 29, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.)

  • CVE-2018-18784HigOct 29, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.)

  • CVE-2018-17798MedSep 30, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in zzcms 8.3. user/ztconfig.php allows remote attackers to delete arbitrary files via an absolute pathname in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2018-17797MedSep 30, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

  • CVE-2025-13171MedNov 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

  • CVE-2024-10293MedOct 23, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/class/functions.php. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack…

  • CVE-2024-10292MedOct 23, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be initiated remotely. The…

  • CVE-2024-10291MedOct 23, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_DoExecSQL/Ebak_DotranExecutSQL of the file 3/Ebak5.1/upload/phome.php. The manipulation of the argument phome leads to sql injection. The attack can be initiated…

  • CVE-2023-5263MedSep 29, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of the file /admin/save.php of the component Database Backup File Handler. The manipulation leads to permission issues. The attack may be launched remotely. The…

  • CVE-2024-44820MedSep 4, 2024
    risk 0.40cvss 6.1epss 0.00

    A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed…

  • CVE-2024-44819MedSep 4, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component.