Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Zzzcms CRITICAL 9.8
CVE-2023-45554

File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, j…

No fix yet
Fix from $2,300 2023-10-25
Zzzcms HIGH 7.8
CVE-2023-45555

File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php…

No fix yet
Fix from $1,950 2023-10-25
Zzzcms MEDIUM 5.4
CVE-2023-5582

A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown processing of the component Per…

No fix yet
Fix from $1,600 2023-10-14
Zzzcms HIGH 8.8
CVE-2023-5263

A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of the file /admin/save.php of t…

No fix yet
Fix from $1,950 2023-09-29
Zzzphp CRITICAL 9.8
CVE-2022-23881EPSS 57%

ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.

No fix yet
Fix from $2,300 2022-03-23
Zzzcms HIGH 8.8
CVE-2020-19682

A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.

No fix yet
Fix from $1,950 2021-12-09
Zzzcms MEDIUM 5.4
CVE-2020-19683

A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.

No fix yet
Fix from $1,600 2021-12-09
Zzzphp CRITICAL 9.8
CVE-2020-24877

A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.

No fix yet
Fix from $2,300 2021-03-15
Zzzphp CRITICAL 9.8
CVE-2020-18717

SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.

No fix yet
Fix from $2,300 2021-02-05
Zzzphp CRITICAL 9.8
CVE-2020-20298

Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to ex…

No fix yet
Fix from $2,300 2020-12-18
Zzzphp CRITICAL 9.8
CVE-2019-17408

parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be…

No fix yet
Fix from $2,300 2019-10-14
Zzzphp CRITICAL 9.8
CVE-2019-16722

ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.

No fix yet
Fix from $2,300 2019-09-23
Zzzphp HIGH 7.5
CVE-2019-16720

ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by…

No fix yet
Fix from $1,950 2019-09-23
Zzzphp CRITICAL 9.8
CVE-2019-10647EPSS 7%

ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage…

No fix yet
Fix from $2,300 2019-03-30
Zzzphp HIGH 8.8
CVE-2019-9182

There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the fi…

No fix yet
Fix from $1,950 2019-02-26
Zzzphp HIGH 7.2
CVE-2019-9041EPSS 31%

An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting …

No fix yet
Fix from $1,950 2019-02-23
Zzzphp HIGH 7.5
CVE-2018-20127

An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension…

No fix yet
Fix from $1,950 2018-12-13