Known Vulnerabilities for products from Cszcms

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Cszcms".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-41601 json Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitra... 6.1 - MEDIUM 2023-09-06 2023-09-11
CVE-2023-39599 json Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload ... 5.4 - MEDIUM 2023-08-22 2023-08-28
CVE-2023-38911 json A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload ... 5.4 - MEDIUM 2023-08-18 2023-08-22
CVE-2023-38910 json CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML vi... 6.1 - MEDIUM 2023-08-18 2023-08-22
CVE-2022-28997 json CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data ... 7.5 - HIGH 2022-05-23 2022-06-03
CVE-2022-27165 json CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus 9.8 - CRITICAL 2022-04-12 2022-04-18
CVE-2022-27164 json CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers 9.8 - CRITICAL 2022-04-12 2022-04-18
CVE-2022-27163 json CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser 9.8 - CRITICAL 2022-04-12 2022-04-18
CVE-2022-27162 json CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser 9.8 - CRITICAL 2022-04-12 2022-04-18
CVE-2022-27161 json Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers 9.8 - CRITICAL 2022-04-12 2022-04-18
CVE-2021-43701 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.5 - MEDIUM 2022-03-29 2022-04-05
CVE-2021-37144 json CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user inpu... 9.1 - CRITICAL 2021-07-30 2021-08-09
CVE-2021-26776 json CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name. 5.4 - MEDIUM 2021-03-11 2021-03-17
CVE-2021-3224 json A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter. 5.4 - MEDIUM 2021-03-10 2021-03-12
CVE-2020-25392 json A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a c... 5.4 - MEDIUM 2021-07-09 2021-07-12
CVE-2020-25391 json A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted... 5.4 - MEDIUM 2021-07-09 2021-07-12
CVE-2020-21250 json CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php. 9.8 - CRITICAL 2021-10-27 2021-10-28
CVE-2020-19786 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 8.8 - HIGH 2023-03-23 2023-03-30
CVE-2019-15524 json CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module... 9.8 - CRITICAL 2019-08-26 2019-08-30
CVE-2019-13086 json core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-A... 9.8 - CRITICAL 2019-06-30 2019-07-03

Known software with vulnerabilities from Cszcms

Type Vendor Product Version
ApplicationCszcmsCsz Cms1.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report