Zkea

Zkeacms

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 21.09.2025 07:02:05
  • Zuletzt bearbeitet 14.10.2025 19:59:30

A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file EventViewerController.cs. Executing manipulation of the argument ID can lead to path traversal. It is possible to launch the attack rem...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 21.09.2025 06:32:06
  • Zuletzt bearbeitet 14.10.2025 19:44:35

A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Suggestions in the library cms-v4.3\wwwroot\Plugins\ZKEACMS.SEOSuggestions\ZKEACMS.SEOSuggestions.dll of the component SEOSuggestions...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 21.09.2025 05:32:05
  • Zuletzt bearbeitet 14.10.2025 19:44:06

A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs of the component Event Action System. Such manipulation of the argument Data leads t...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 15.09.2025 16:32:07
  • Zuletzt bearbeitet 14.10.2025 19:34:04

A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaController.cs. Performing manipulation of the argument url results in server-side request forgery. It is possible to initiate the att...

  • EPSS 0.12%
  • Veröffentlicht 04.08.2025 00:00:00
  • Zuletzt bearbeitet 14.08.2025 16:10:59

An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 25.05.2022 01:15:07
  • Zuletzt bearbeitet 14.08.2025 16:13:05

A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ParentID parameter.

Exploit
  • EPSS 0.71%
  • Veröffentlicht 13.09.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 05:12:12

An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file.