Cszcms records
30 published records for vendor cszcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-706 Use of Incorrectly-Resolved Name or Reference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2019-13086Proof of concept | core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header andcszcms · csz cms · CWE-89 | Critical9.8 | — | 32.0% | Jun 30, 2019 |
40Plan | CVE-2019-15524No exploit | CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads tcszcms · csz cms · CWE-434 | Critical9.8 | — | 3.1% | Aug 26, 2019 |
39Monitor | CVE-2024-25414No exploit | An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a craftecszcms · csz cms · CWE-434 | Critical9.8 | — | 1.6% | Feb 15, 2024 |
39Monitor | CVE-2022-27161No exploit | Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUserscszcms · csz cms · CWE-89 | Critical9.8 | — | 1.3% | Apr 12, 2022 |
39Monitor | CVE-2020-21250No exploit | CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.cszcms · csz cms · CWE-89 | Critical9.8 | — | 1.2% | Oct 27, 2021 |
39Monitor | CVE-2022-27163No exploit | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUsercszcms · csz cms · CWE-89 | Critical9.8 | — | 1.2% | Apr 12, 2022 |
39Monitor | CVE-2022-27165No exploit | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatuscszcms · csz cms · CWE-89 | Critical9.8 | — | 1.1% | Apr 12, 2022 |
39Monitor | CVE-2022-27164No exploit | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUserscszcms · csz cms · CWE-89 | Critical9.8 | — | 1.1% | Apr 12, 2022 |
39Monitor | CVE-2022-27162No exploit | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUsercszcms · csz cms · CWE-89 | Critical9.8 | — | 1.1% | Apr 12, 2022 |
37Monitor | CVE-2024-58307No exploit | CSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpointcszcms · csz cms · CWE-89 | Critical9.3 | — | 0.5% | Dec 11, 2025 |
36Monitor | CVE-2021-37144No exploit | CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.cszcms · csz cms · CWE-706 | Critical9.1 | — | 1.3% | Jul 30, 2021 |
35Monitor | CVE-2020-19786No exploit | File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP ficszcms · csz cms · CWE-434 | High8.8 | — | 0.8% | Mar 23, 2023 |
35Monitor | CVE-2019-7566No exploit | CSZ CMS 1.1.8 has CSRF via admin/users/new/add.cszcms · csz cms · CWE-352 | High8.8 | — | 0.7% | Feb 7, 2019 |
31Monitor | CVE-2022-28997No exploit | CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local filcszcms · cszcms · CWE-918 | High7.5 | — | 2.0% | May 23, 2022 |
27Monitor | CVE-2021-43701Proof of concept | CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldScszcms · csz cms · CWE-89 | Medium6.5 | — | 3.3% | Mar 29, 2022 |
26Monitor | CVE-2025-29083No exploit | SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugincszcms · csz cms · CWE-77 | Medium6.5 | — | 0.4% | Sep 23, 2025 |
26Monitor | CVE-2025-29084No exploit | SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Upgradcszcms · csz cms · CWE-89 | Medium6.5 | — | 0.4% | Sep 23, 2025 |
24Monitor | CVE-2023-38910No exploit | CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted paycszcms · csz cms · CWE-79 | Medium6.1 | — | 0.5% | Aug 18, 2023 |
24Monitor | CVE-2024-27734No exploit | A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the Site Name fcszcms · csz cms · CWE-79 | Medium6.1 | — | 0.5% | Mar 1, 2024 |
24Monitor | CVE-2023-41601No exploit | Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts cszcms · csz cms · CWE-79 | Medium6.1 | — | 0.4% | Sep 6, 2023 |
21Monitor | CVE-2024-27752No exploit | Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in thcszcms · csz cms · CWE-79 | Medium5.4 | — | 0.6% | Apr 19, 2024 |
21Monitor | CVE-2021-3224No exploit | A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.cszcms · csz cms · CWE-79 | Medium5.4 | — | 0.5% | Mar 10, 2021 |
21Monitor | CVE-2021-26776No exploit | CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.cszcms · csz cms · CWE-79 | Medium5.4 | — | 0.5% | Mar 11, 2021 |
21Monitor | CVE-2023-39599No exploit | Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Scszcms · csz cms · CWE-79 | Medium5.4 | — | 0.5% | Aug 22, 2023 |
21Monitor | CVE-2023-38911No exploit | A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery cszcms · csz cms · CWE-79 | Medium5.4 | — | 0.5% | Aug 18, 2023 |
- CVE-2019-1308649Plan
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and
CriticalCVSS 9.8Proof of conceptEPSS 32%cszcms · csz cmsJun 30, 2019
- CVE-2019-1552440Plan
CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads t
CriticalCVSS 9.8No exploitEPSS 3%cszcms · csz cmsAug 26, 2019
- CVE-2024-2541439Monitor
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafte
CriticalCVSS 9.8No exploitEPSS 2%cszcms · csz cmsFeb 15, 2024
- CVE-2022-2716139Monitor
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
CriticalCVSS 9.8No exploitEPSS 1%cszcms · csz cmsApr 12, 2022
- CVE-2020-2125039Monitor
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
CriticalCVSS 9.8No exploitEPSS 1%cszcms · csz cmsOct 27, 2021
- CVE-2022-2716339Monitor
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
CriticalCVSS 9.8No exploitEPSS 1%cszcms · csz cmsApr 12, 2022
- CVE-2022-2716539Monitor
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
CriticalCVSS 9.8No exploitEPSS 1%cszcms · csz cmsApr 12, 2022
- CVE-2022-2716439Monitor
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
CriticalCVSS 9.8No exploitEPSS 1%cszcms · csz cmsApr 12, 2022
- CVE-2022-2716239Monitor
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
CriticalCVSS 9.8No exploitEPSS 1%cszcms · csz cmsApr 12, 2022
- CVE-2024-5830737Monitor
CSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpoint
CriticalCVSS 9.3No exploitEPSS 1%cszcms · csz cmsDec 11, 2025
- CVE-2021-3714436Monitor
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.
CriticalCVSS 9.1No exploitEPSS 1%cszcms · csz cmsJul 30, 2021
- CVE-2020-1978635Monitor
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP fi
HighCVSS 8.8No exploitEPSS 1%cszcms · csz cmsMar 23, 2023
- CVE-2019-756635Monitor
CSZ CMS 1.1.8 has CSRF via admin/users/new/add.
HighCVSS 8.8No exploitEPSS 1%cszcms · csz cmsFeb 7, 2019
- CVE-2022-2899731Monitor
CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local fil
HighCVSS 7.5No exploitEPSS 2%cszcms · cszcmsMay 23, 2022
- CVE-2021-4370127Monitor
CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS
MediumCVSS 6.5Proof of conceptEPSS 3%cszcms · csz cmsMar 29, 2022
- CVE-2025-2908326Monitor
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugin
MediumCVSS 6.5No exploitEPSS 0%cszcms · csz cmsSep 23, 2025
- CVE-2025-2908426Monitor
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Upgrad
MediumCVSS 6.5No exploitEPSS 0%cszcms · csz cmsSep 23, 2025
- CVE-2023-3891024Monitor
CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted pay
MediumCVSS 6.1No exploitEPSS 0%cszcms · csz cmsAug 18, 2023
- CVE-2024-2773424Monitor
A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the Site Name f
MediumCVSS 6.1No exploitEPSS 0%cszcms · csz cmsMar 1, 2024
- CVE-2023-4160124Monitor
Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts
MediumCVSS 6.1No exploitEPSS 0%cszcms · csz cmsSep 6, 2023
- CVE-2024-2775221Monitor
Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in th
MediumCVSS 5.4No exploitEPSS 1%cszcms · csz cmsApr 19, 2024
- CVE-2021-322421Monitor
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.
MediumCVSS 5.4No exploitEPSS 1%cszcms · csz cmsMar 10, 2021
- CVE-2021-2677621Monitor
CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
MediumCVSS 5.4No exploitEPSS 1%cszcms · csz cmsMar 11, 2021
- CVE-2023-3959921Monitor
Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social S
MediumCVSS 5.4No exploitEPSS 1%cszcms · csz cmsAug 22, 2023
- CVE-2023-3891121Monitor
A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery
MediumCVSS 5.4No exploitEPSS 0%cszcms · csz cmsAug 18, 2023