Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zzcms zzcms vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2019-12359
An issue exists in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.
Zzcms Zzcms 2019
6.5
CVSSv3
CVE-2018-17797
An issue exists in zzcms 8.3. user/zssave.php allows remote malicious users to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.3
6.5
CVSSv3
CVE-2018-17798
An issue exists in zzcms 8.3. user/ztconfig.php allows remote malicious users to delete arbitrary files via an absolute pathname in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.3
5.4
CVSSv3
CVE-2020-20285
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
Zzcms Zzcms 2019
5.4
CVSSv3
CVE-2020-35973
An issue exists in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.
Zzcms Zzcms 2020
7.2
CVSSv3
CVE-2021-46436
An issue exists in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.
Zzcms Zzcms 2021
8.8
CVSSv3
CVE-2023-36162
Cross Site Request Forgery vulnerability in ZZCMS v.2023 and previous versions allows a remote malicious user to gain privileges via the add function in adminlist.php.
Zzcms Zzcms 2023
7.5
CVSSv3
CVE-2018-16344
An issue exists in zzcms 8.3. It allows remote malicious users to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.3
7.5
CVSSv3
CVE-2020-19957
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows malicious users to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.
Zzcms Zzcms 2019
7.5
CVSSv3
CVE-2020-19961
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows malicious users to retrieve sensitive data via the component subzs.php.
Zzcms Zzcms 2019
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »