zzzcms records
20 published records for vendor zzzcms.
Researcher profile
- Entered KEV
- 1 · 5%
- Weaponized
- 1 · 5%
- Pre-auth RCE
- 9
- With a fix record
- 0%
- Median publish → KEV
- 983 days
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
94Now | CVE-2019-9082Weaponized | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\appthinkphp · thinkphp · CWE-94 | High8.8 | KEV | 97.4% | Feb 24, 2019 |
56Plan | CVE-2022-23881Proof of concept | ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.zzzcms · zzzphp | Critical9.8 | — | 56.5% | Mar 23, 2022 |
41Plan | CVE-2019-10647Proof of concept | ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=czzzcms · zzzphp · CWE-434 | Critical9.8 | — | 6.6% | Mar 30, 2019 |
40Plan | CVE-2021-32605No exploit | zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=seazzzcms · zzzphp · CWE-78 | Critical9.8 | — | 3.8% | May 11, 2021 |
40Plan | CVE-2019-17408No exploit | parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key functizzzcms · zzzphp · CWE-94 | Critical9.8 | — | 3.7% | Oct 14, 2019 |
40Plan | CVE-2020-18717No exploit | SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_templzzzcms · zzzphp · CWE-89 | Critical9.8 | — | 3.6% | Feb 5, 2021 |
40Plan | CVE-2019-16722No exploit | ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operatiozzzcms · zzzphp | Critical9.8 | — | 3.1% | Sep 23, 2019 |
40Plan | CVE-2020-20298No exploit | Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackzzzcms · zzzphp · CWE-94 | Critical9.8 | — | 2.7% | Dec 18, 2020 |
40Plan | CVE-2020-24877No exploit | A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.zzzcms · zzzphp · CWE-89 | Critical9.8 | — | 2.1% | Mar 15, 2021 |
39Monitor | CVE-2023-45554No exploit | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter frzzzcms · zzzcms · CWE-434 | Critical9.8 | — | 1.5% | Oct 25, 2023 |
37Monitor | CVE-2019-9041Proof of concept | An issue was discovered in ZZZCMS zzzphp V1.6.1.zzzcms · zzzphp · CWE-917 | High7.2 | — | 31.4% | Feb 23, 2019 |
35Monitor | CVE-2019-9182No exploit | There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request.zzzcms · zzzphp · CWE-352 | High8.8 | — | 0.8% | Feb 26, 2019 |
35Monitor | CVE-2023-5263No exploit | ZZZCMS Database Backup File save.php restore permissionzzzcms · zzzcms · CWE-275 | High8.8 | — | 0.7% | Sep 29, 2023 |
35Monitor | CVE-2020-19682No exploit | A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.zzzcms · zzzcms · CWE-352 | High8.8 | — | 0.5% | Dec 9, 2021 |
31Monitor | CVE-2023-45555No exploit | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function izzzcms · zzzcms · CWE-434 | High7.8 | — | 0.9% | Oct 25, 2023 |
30Monitor | CVE-2019-16720No exploit | ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonszzzcms · zzzphp · CWE-434 | High7.5 | — | 1.4% | Sep 23, 2019 |
30Monitor | CVE-2018-20127No exploit | An issue was discovered in zzzphp cms 1.5.8.zzzcms · zzzphp · CWE-20 | High7.5 | — | 1.4% | Dec 13, 2018 |
24Monitor | CVE-2023-45909No exploit | zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.zzzcms · zzzphp · CWE-601 | Medium6.1 | — | 0.3% | Oct 18, 2023 |
21Monitor | CVE-2020-19683No exploit | A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.zzzcms · zzzcms · CWE-79 | Medium5.4 | — | 0.6% | Dec 9, 2021 |
21Monitor | CVE-2023-5582No exploit | ZZZCMS Personal Profile Page cross site scriptingzzzcms · zzzcms · CWE-80 | Medium5.4 | — | 0.5% | Oct 14, 2023 |
- CVE-2019-908294Now
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app
HighCVSS 8.8KEVWeaponizedEPSS 97%thinkphp · thinkphpFeb 24, 2019
- CVE-2022-2388156Plan
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
CriticalCVSS 9.8Proof of conceptEPSS 57%zzzcms · zzzphpMar 23, 2022
- CVE-2019-1064741Plan
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=c
CriticalCVSS 9.8Proof of conceptEPSS 7%zzzcms · zzzphpMar 30, 2019
- CVE-2021-3260540Plan
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=sea
CriticalCVSS 9.8No exploitEPSS 4%zzzcms · zzzphpMay 11, 2021
- CVE-2019-1740840Plan
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key functi
CriticalCVSS 9.8No exploitEPSS 4%zzzcms · zzzphpOct 14, 2019
- CVE-2020-1871740Plan
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_templ
CriticalCVSS 9.8No exploitEPSS 4%zzzcms · zzzphpFeb 5, 2021
- CVE-2019-1672240Plan
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operatio
CriticalCVSS 9.8No exploitEPSS 3%zzzcms · zzzphpSep 23, 2019
- CVE-2020-2029840Plan
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attack
CriticalCVSS 9.8No exploitEPSS 3%zzzcms · zzzphpDec 18, 2020
- CVE-2020-2487740Plan
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
CriticalCVSS 9.8No exploitEPSS 2%zzzcms · zzzphpMar 15, 2021
- CVE-2023-4555439Monitor
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter fr
CriticalCVSS 9.8No exploitEPSS 2%zzzcms · zzzcmsOct 25, 2023
- CVE-2019-904137Monitor
An issue was discovered in ZZZCMS zzzphp V1.6.1.
HighCVSS 7.2Proof of conceptEPSS 31%zzzcms · zzzphpFeb 23, 2019
- CVE-2019-918235Monitor
There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request.
HighCVSS 8.8No exploitEPSS 1%zzzcms · zzzphpFeb 26, 2019
- CVE-2023-526335Monitor
ZZZCMS Database Backup File save.php restore permission
HighCVSS 8.8No exploitEPSS 1%zzzcms · zzzcmsSep 29, 2023
- CVE-2020-1968235Monitor
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.
HighCVSS 8.8No exploitEPSS 1%zzzcms · zzzcmsDec 9, 2021
- CVE-2023-4555531Monitor
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function i
HighCVSS 7.8No exploitEPSS 1%zzzcms · zzzcmsOct 25, 2023
- CVE-2019-1672030Monitor
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demons
HighCVSS 7.5No exploitEPSS 1%zzzcms · zzzphpSep 23, 2019
- CVE-2018-2012730Monitor
An issue was discovered in zzzphp cms 1.5.8.
HighCVSS 7.5No exploitEPSS 1%zzzcms · zzzphpDec 13, 2018
- CVE-2023-4590924Monitor
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
MediumCVSS 6.1No exploitEPSS 0%zzzcms · zzzphpOct 18, 2023
- CVE-2020-1968321Monitor
A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.
MediumCVSS 5.4No exploitEPSS 1%zzzcms · zzzcmsDec 9, 2021
- CVE-2023-558221Monitor
ZZZCMS Personal Profile Page cross site scripting
MediumCVSS 5.4No exploitEPSS 1%zzzcms · zzzcmsOct 14, 2023