Known Vulnerabilities for products from Cszcms
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Cszcms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-41601 json | Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitra... | 6.1 - MEDIUM | 2023-09-06 | 2023-09-11 |
| CVE-2023-39599 json | Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload ... | 5.4 - MEDIUM | 2023-08-22 | 2023-08-28 |
| CVE-2023-38911 json | A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload ... | 5.4 - MEDIUM | 2023-08-18 | 2023-08-22 |
| CVE-2023-38910 json | CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML vi... | 6.1 - MEDIUM | 2023-08-18 | 2023-08-22 |
| CVE-2022-28997 json | CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data ... | 7.5 - HIGH | 2022-05-23 | 2022-06-03 |
| CVE-2022-27165 json | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus | 9.8 - CRITICAL | 2022-04-12 | 2022-04-18 |
| CVE-2022-27164 json | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers | 9.8 - CRITICAL | 2022-04-12 | 2022-04-18 |
| CVE-2022-27163 json | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser | 9.8 - CRITICAL | 2022-04-12 | 2022-04-18 |
| CVE-2022-27162 json | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser | 9.8 - CRITICAL | 2022-04-12 | 2022-04-18 |
| CVE-2022-27161 json | Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers | 9.8 - CRITICAL | 2022-04-12 | 2022-04-18 |
| CVE-2021-43701 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2022-03-29 | 2022-04-05 |
| CVE-2021-37144 json | CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user inpu... | 9.1 - CRITICAL | 2021-07-30 | 2021-08-09 |
| CVE-2021-26776 json | CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name. | 5.4 - MEDIUM | 2021-03-11 | 2021-03-17 |
| CVE-2021-3224 json | A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter. | 5.4 - MEDIUM | 2021-03-10 | 2021-03-12 |
| CVE-2020-25392 json | A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a c... | 5.4 - MEDIUM | 2021-07-09 | 2021-07-12 |
| CVE-2020-25391 json | A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted... | 5.4 - MEDIUM | 2021-07-09 | 2021-07-12 |
| CVE-2020-21250 json | CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php. | 9.8 - CRITICAL | 2021-10-27 | 2021-10-28 |
| CVE-2020-19786 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-03-23 | 2023-03-30 |
| CVE-2019-15524 json | CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module... | 9.8 - CRITICAL | 2019-08-26 | 2019-08-30 |
| CVE-2019-13086 json | core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-A... | 9.8 - CRITICAL | 2019-06-30 | 2019-07-03 |
Known software with vulnerabilities from Cszcms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Cszcms | Csz Cms | 1.0.0 |