Vulnerabilities > Zzcms > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-05-24 | CVE-2019-12348 | SQL Injection vulnerability in Zzcms 2019 An issue was discovered in zzcms 2019. | 9.8 |
2021-04-08 | CVE-2020-23426 | Cross-Site Request Forgery (CSRF) vulnerability in Zzcms 201910 zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF. | 9.8 |
2019-07-23 | CVE-2019-1010153 | SQL Injection vulnerability in Zzcms zzcms 8.3 and earlier is affected by: SQL Injection. | 9.8 |
2019-07-23 | CVE-2019-1010152 | Missing Authorization vulnerability in Zzcms zzcms 8.3 and earlier is affected by: File Delete to Code Execution. | 9.8 |
2019-07-23 | CVE-2019-1010150 | Missing Authorization vulnerability in Zzcms zzcms 8.3 and earlier is affected by: File Delete to Code Execution. | 9.8 |
2019-07-23 | CVE-2019-1010149 | Missing Authorization vulnerability in Zzcms zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. | 9.8 |
2019-07-23 | CVE-2019-1010148 | SQL Injection vulnerability in Zzcms zzcms version 8.3 and earlier is affected by: SQL Injection. | 9.8 |
2019-07-19 | CVE-2019-1010151 | Path Traversal vulnerability in Zzcms Zzmcms 8.3 zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. | 9.8 |
2019-03-07 | CVE-2018-17412 | SQL Injection vulnerability in Zzcms 8.3 zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header. | 9.8 |
2018-10-29 | CVE-2018-18792 | SQL Injection vulnerability in Zzcms 8.3 An issue was discovered in zzcms 8.3. | 9.8 |