Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-63693 The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in m… Dzzoffice after 2.3.7 Fix from $1,6002025-11-18 CRITICAL 9.8 CVE-2025-63694 DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage. Dzzoffice after 2.3.7 Fix from $2,3002025-11-18 CRITICAL 9.8 CVE-2025-63695 DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php. Dzzoffice after 2.3.7 Fix from $2,3002025-11-18 HIGH 8.8 CVE-2024-41376 dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php. Dzzoffice No fix yet Fix from $1,9502024-08-05 MEDIUM 6.1 CVE-2024-29273 There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document. Dzzoffice No fix yet Fix from $1,6002024-03-22 MEDIUM 6.5 CVE-2023-39853 SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent parameters i… Dzzoffice No fix yet Fix from $1,6002024-01-06 MEDIUM 6.1 CVE-2021-30203 A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scri… Dzzoffice No fix yet Fix from $1,6002023-06-27 MEDIUM 5.3 CVE-2021-30205 Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse dep… Dzzoffice No fix yet Fix from $1,6002023-06-27 HIGH 8.8 CVE-2022-43340 A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights t… Dzzoffice Mitigation only Fix from $1,9502022-10-27 MEDIUM 6.1 CVE-2021-43673 dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed fo… Dzzoffice No fix yet Fix from $1,6002021-12-03 MEDIUM 5.4 CVE-2021-40292 A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter. Dzzoffice No fix yet Fix from $1,6002021-10-12 MEDIUM 5.4 CVE-2021-40191 Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz… Dzzoffice No fix yet Fix from $1,6002021-10-11 MEDIUM 6.1 CVE-2020-19703 A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a… Dzzoffice No fix yet Fix from $1,6002021-08-26 MEDIUM 6.1 CVE-2021-3318 attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter. Dzzoffice after 2.02.1 Fix from $1,6002021-01-27