Cszcms kayıtları
cszcms üreticisine ait 30 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-706 Use of Incorrectly-Resolved Name or Reference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
30 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2019-13086Kavram kanıtı | core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header andcszcms · csz cms · CWE-89 | Kritik9,8 | — | %32,0 | 30 Haz 2019 |
40Planlayın | CVE-2019-15524İstismar yok | CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads tcszcms · csz cms · CWE-434 | Kritik9,8 | — | %3,1 | 26 Ağu 2019 |
39İzleyin | CVE-2024-25414İstismar yok | An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a craftecszcms · csz cms · CWE-434 | Kritik9,8 | — | %1,6 | 15 Şub 2024 |
39İzleyin | CVE-2022-27161İstismar yok | Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUserscszcms · csz cms · CWE-89 | Kritik9,8 | — | %1,3 | 12 Nis 2022 |
39İzleyin | CVE-2020-21250İstismar yok | CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.cszcms · csz cms · CWE-89 | Kritik9,8 | — | %1,2 | 27 Eki 2021 |
39İzleyin | CVE-2022-27163İstismar yok | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUsercszcms · csz cms · CWE-89 | Kritik9,8 | — | %1,2 | 12 Nis 2022 |
39İzleyin | CVE-2022-27165İstismar yok | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatuscszcms · csz cms · CWE-89 | Kritik9,8 | — | %1,1 | 12 Nis 2022 |
39İzleyin | CVE-2022-27164İstismar yok | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUserscszcms · csz cms · CWE-89 | Kritik9,8 | — | %1,1 | 12 Nis 2022 |
39İzleyin | CVE-2022-27162İstismar yok | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUsercszcms · csz cms · CWE-89 | Kritik9,8 | — | %1,1 | 12 Nis 2022 |
37İzleyin | CVE-2024-58307İstismar yok | CSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpointcszcms · csz cms · CWE-89 | Kritik9,3 | — | %0,5 | 11 Ara 2025 |
36İzleyin | CVE-2021-37144İstismar yok | CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.cszcms · csz cms · CWE-706 | Kritik9,1 | — | %1,3 | 30 Tem 2021 |
35İzleyin | CVE-2020-19786İstismar yok | File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP ficszcms · csz cms · CWE-434 | Yüksek8,8 | — | %0,8 | 23 Mar 2023 |
35İzleyin | CVE-2019-7566İstismar yok | CSZ CMS 1.1.8 has CSRF via admin/users/new/add.cszcms · csz cms · CWE-352 | Yüksek8,8 | — | %0,7 | 7 Şub 2019 |
31İzleyin | CVE-2022-28997İstismar yok | CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local filcszcms · cszcms · CWE-918 | Yüksek7,5 | — | %2,0 | 23 May 2022 |
27İzleyin | CVE-2021-43701Kavram kanıtı | CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldScszcms · csz cms · CWE-89 | Orta6,5 | — | %3,3 | 29 Mar 2022 |
26İzleyin | CVE-2025-29083İstismar yok | SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugincszcms · csz cms · CWE-77 | Orta6,5 | — | %0,4 | 23 Eyl 2025 |
26İzleyin | CVE-2025-29084İstismar yok | SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Upgradcszcms · csz cms · CWE-89 | Orta6,5 | — | %0,4 | 23 Eyl 2025 |
24İzleyin | CVE-2023-38910İstismar yok | CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted paycszcms · csz cms · CWE-79 | Orta6,1 | — | %0,5 | 18 Ağu 2023 |
24İzleyin | CVE-2024-27734İstismar yok | A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the Site Name fcszcms · csz cms · CWE-79 | Orta6,1 | — | %0,5 | 1 Mar 2024 |
24İzleyin | CVE-2023-41601İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts cszcms · csz cms · CWE-79 | Orta6,1 | — | %0,4 | 6 Eyl 2023 |
21İzleyin | CVE-2024-27752İstismar yok | Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in thcszcms · csz cms · CWE-79 | Orta5,4 | — | %0,6 | 19 Nis 2024 |
21İzleyin | CVE-2021-3224İstismar yok | A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.cszcms · csz cms · CWE-79 | Orta5,4 | — | %0,5 | 10 Mar 2021 |
21İzleyin | CVE-2021-26776İstismar yok | CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.cszcms · csz cms · CWE-79 | Orta5,4 | — | %0,5 | 11 Mar 2021 |
21İzleyin | CVE-2023-39599İstismar yok | Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Scszcms · csz cms · CWE-79 | Orta5,4 | — | %0,5 | 22 Ağu 2023 |
21İzleyin | CVE-2023-38911İstismar yok | A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery cszcms · csz cms · CWE-79 | Orta5,4 | — | %0,5 | 18 Ağu 2023 |
- CVE-2019-1308649Planlayın
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and
KritikCVSS 9,8Kavram kanıtıEPSS %32cszcms · csz cms30 Haz 2019
- CVE-2019-1552440Planlayın
CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads t
KritikCVSS 9,8İstismar yokEPSS %3cszcms · csz cms26 Ağu 2019
- CVE-2024-2541439İzleyin
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafte
KritikCVSS 9,8İstismar yokEPSS %2cszcms · csz cms15 Şub 2024
- CVE-2022-2716139İzleyin
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
KritikCVSS 9,8İstismar yokEPSS %1cszcms · csz cms12 Nis 2022
- CVE-2020-2125039İzleyin
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
KritikCVSS 9,8İstismar yokEPSS %1cszcms · csz cms27 Eki 2021
- CVE-2022-2716339İzleyin
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
KritikCVSS 9,8İstismar yokEPSS %1cszcms · csz cms12 Nis 2022
- CVE-2022-2716539İzleyin
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
KritikCVSS 9,8İstismar yokEPSS %1cszcms · csz cms12 Nis 2022
- CVE-2022-2716439İzleyin
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
KritikCVSS 9,8İstismar yokEPSS %1cszcms · csz cms12 Nis 2022
- CVE-2022-2716239İzleyin
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
KritikCVSS 9,8İstismar yokEPSS %1cszcms · csz cms12 Nis 2022
- CVE-2024-5830737İzleyin
CSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpoint
KritikCVSS 9,3İstismar yokEPSS %1cszcms · csz cms11 Ara 2025
- CVE-2021-3714436İzleyin
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.
KritikCVSS 9,1İstismar yokEPSS %1cszcms · csz cms30 Tem 2021
- CVE-2020-1978635İzleyin
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP fi
YüksekCVSS 8,8İstismar yokEPSS %1cszcms · csz cms23 Mar 2023
- CVE-2019-756635İzleyin
CSZ CMS 1.1.8 has CSRF via admin/users/new/add.
YüksekCVSS 8,8İstismar yokEPSS %1cszcms · csz cms7 Şub 2019
- CVE-2022-2899731İzleyin
CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local fil
YüksekCVSS 7,5İstismar yokEPSS %2cszcms · cszcms23 May 2022
- CVE-2021-4370127İzleyin
CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS
OrtaCVSS 6,5Kavram kanıtıEPSS %3cszcms · csz cms29 Mar 2022
- CVE-2025-2908326İzleyin
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugin
OrtaCVSS 6,5İstismar yokEPSS %0cszcms · csz cms23 Eyl 2025
- CVE-2025-2908426İzleyin
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Upgrad
OrtaCVSS 6,5İstismar yokEPSS %0cszcms · csz cms23 Eyl 2025
- CVE-2023-3891024İzleyin
CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted pay
OrtaCVSS 6,1İstismar yokEPSS %0cszcms · csz cms18 Ağu 2023
- CVE-2024-2773424İzleyin
A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the Site Name f
OrtaCVSS 6,1İstismar yokEPSS %0cszcms · csz cms1 Mar 2024
- CVE-2023-4160124İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts
OrtaCVSS 6,1İstismar yokEPSS %0cszcms · csz cms6 Eyl 2023
- CVE-2024-2775221İzleyin
Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in th
OrtaCVSS 5,4İstismar yokEPSS %1cszcms · csz cms19 Nis 2024
- CVE-2021-322421İzleyin
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.
OrtaCVSS 5,4İstismar yokEPSS %1cszcms · csz cms10 Mar 2021
- CVE-2021-2677621İzleyin
CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
OrtaCVSS 5,4İstismar yokEPSS %1cszcms · csz cms11 Mar 2021
- CVE-2023-3959921İzleyin
Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social S
OrtaCVSS 5,4İstismar yokEPSS %1cszcms · csz cms22 Ağu 2023
- CVE-2023-3891121İzleyin
A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery
OrtaCVSS 5,4İstismar yokEPSS %0cszcms · csz cms18 Ağu 2023