Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dzzoffice MEDIUM 5.4
CVE-2025-63693

The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in m…

Fix: after 2.3.7
Fix from $1,600 2025-11-18
Dzzoffice CRITICAL 9.8
CVE-2025-63694

DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.

Fix: after 2.3.7
Fix from $2,300 2025-11-18
Dzzoffice CRITICAL 9.8
CVE-2025-63695

DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.

Fix: after 2.3.7
Fix from $2,300 2025-11-18
Dzzoffice HIGH 8.8
CVE-2024-41376

dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

No fix yet
Fix from $1,950 2024-08-05
Dzzoffice MEDIUM 6.1
CVE-2024-29273

There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

No fix yet
Fix from $1,600 2024-03-22
Dzzoffice MEDIUM 6.5
CVE-2023-39853

SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent parameters i…

No fix yet
Fix from $1,600 2024-01-06
Dzzoffice MEDIUM 6.1
CVE-2021-30203

A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scri…

No fix yet
Fix from $1,600 2023-06-27
Dzzoffice MEDIUM 5.3
CVE-2021-30205

Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse dep…

No fix yet
Fix from $1,600 2023-06-27
Dzzoffice HIGH 8.8
CVE-2022-43340

A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights t…

Mitigation only
Fix from $1,950 2022-10-27
Dzzoffice MEDIUM 6.1
CVE-2021-43673

dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed fo…

No fix yet
Fix from $1,600 2021-12-03
Dzzoffice MEDIUM 5.4
CVE-2021-40292

A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.

No fix yet
Fix from $1,600 2021-10-12
Dzzoffice MEDIUM 5.4
CVE-2021-40191

Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz…

No fix yet
Fix from $1,600 2021-10-11
Dzzoffice MEDIUM 6.1
CVE-2020-19703

A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a…

No fix yet
Fix from $1,600 2021-08-26
Dzzoffice MEDIUM 6.1
CVE-2021-3318

attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.

Fix: after 2.02.1
Fix from $1,600 2021-01-27