Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zzcms vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2018-17797
An issue exists in zzcms 8.3. user/zssave.php allows remote malicious users to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.3
6.5
CVSSv3
CVE-2018-17798
An issue exists in zzcms 8.3. user/ztconfig.php allows remote malicious users to delete arbitrary files via an absolute pathname in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Zzcms Zzcms 8.3
5.4
CVSSv3
CVE-2022-44361
An issue exists in ZZCMS 2022. There is a cross-site scripting (XSS) vulnerability in admin/ad_list.php.
Zzcms Zzcms 2022
9.8
CVSSv3
CVE-2023-50104
ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing malicious users to exploit this loophole to gain server privileges and execute arbitrary code.
Zzcms Zzcms 2023
8.8
CVSSv3
CVE-2023-36162
Cross Site Request Forgery vulnerability in ZZCMS v.2023 and previous versions allows a remote malicious user to gain privileges via the add function in adminlist.php.
Zzcms Zzcms 2023
9.8
CVSSv3
CVE-2023-42398
An issue in zzCMS v.2023 allows a remote malicious user to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.
Zzcms Zzcms 2023
7.2
CVSSv3
CVE-2021-46436
An issue exists in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.
Zzcms Zzcms 2021
4.8
CVSSv3
CVE-2021-46437
An issue exists in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php.
Zzcms Zzcms 2021
9.8
CVSSv3
CVE-2019-12349
An issue exists in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.
Zzcms Zzcms 2019
7.5
CVSSv3
CVE-2019-8411
admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote malicious users to delete arbitrary files via action=del&filename=../ directory traversal.
Zzcms Zzcms 2018
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4040
privilege escalation
CVE-2024-4112
CVE-2024-32872
man-in-the-middle
CVE-2024-32788
bypass
CVE-2024-3400
CVE-2024-28976
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »