CVE-2025-1949
- EPSS 0.06%
- Veröffentlicht 04.03.2025 19:15:37
- Zuletzt bearbeitet 23.04.2025 15:00:45
A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the component URL Handler. The manipulation of the argument $_SERVER['...
CVE-2025-22957
- EPSS 0.27%
- Veröffentlicht 31.01.2025 17:15:16
- Zuletzt bearbeitet 22.04.2025 15:37:40
A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sen...
CVE-2025-0565
- EPSS 0.13%
- Veröffentlicht 19.01.2025 06:15:06
- Zuletzt bearbeitet 22.04.2025 19:37:16
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The ...
CVE-2024-52724
- EPSS 0.17%
- Veröffentlicht 02.12.2024 19:15:10
- Zuletzt bearbeitet 21.04.2025 16:51:44
ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.
CVE-2024-11242
- EPSS 0.14%
- Veröffentlicht 15.11.2024 15:15:06
- Zuletzt bearbeitet 23.04.2025 15:01:34
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ad_list.php?action=pass of the component Keyword Filtering. The manipulation of the argument keyword leads...
CVE-2024-11130
- EPSS 0.09%
- Veröffentlicht 12.11.2024 15:15:07
- Zuletzt bearbeitet 15.11.2024 17:57:53
A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/msg.php. The manipulation of the argument keyword leads to cross site scripting. The attack may b...
CVE-2024-10293
- EPSS 0.24%
- Veröffentlicht 23.10.2024 16:15:05
- Zuletzt bearbeitet 30.10.2024 13:37:27
A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/class/functions.php. The manipulation of the argument file leads to unrestricted upload. It is possibl...
CVE-2024-10291
- EPSS 0.13%
- Veröffentlicht 23.10.2024 16:15:04
- Zuletzt bearbeitet 30.10.2024 13:23:47
A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_DoExecSQL/Ebak_DotranExecutSQL of the file 3/Ebak5.1/upload/phome.php. The manipulation of the argument phome leads to sql injection...
CVE-2024-10292
- EPSS 0.24%
- Veröffentlicht 23.10.2024 16:15:04
- Zuletzt bearbeitet 30.10.2024 13:40:07
A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be...
CVE-2024-10290
- EPSS 0.15%
- Veröffentlicht 23.10.2024 15:15:30
- Zuletzt bearbeitet 30.10.2024 15:06:00
A vulnerability, which was classified as problematic, was found in ZZCMS 2023. This affects an unknown part of the file 3/qq-connect2.0/API/com/inc.php. The manipulation leads to information disclosure. It is possible to initiate the attack remotely....