Known Vulnerabilities for products from Zikula
Listed below are 11 of the newest known vulnerabilities associated with the vendor "Zikula".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2016-9835 json | Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a... | Not Provided | 2016-12-05 | 2026-05-06 |
| CVE-2014-2293 json | Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete... | 9.8 - CRITICAL | 2018-03-26 | 2018-04-24 |
| CVE-2013-6168 json | Cross-site scripting (XSS) vulnerability in Zikula Application Framework before 1.3.6 allows remote attackers to inject arbit... | Not Provided | 2013-11-14 | 2026-04-29 |
| CVE-2011-3979 json | Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zik... | Not Provided | 2011-10-04 | 2026-04-29 |
| CVE-2011-3826 json | Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the i... | Not Provided | 2011-09-24 | 2026-04-29 |
| CVE-2011-0911 json | Cross-site scripting (XSS) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to inject arbitra... | Not Provided | 2011-02-08 | 2026-04-29 |
| CVE-2011-0535 json | Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack ... | Not Provided | 2011-02-08 | 2026-04-29 |
| CVE-2010-4729 json | Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing,... | Not Provided | 2011-02-08 | 2026-04-29 |
| CVE-2010-4728 json | Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote atta... | Not Provided | 2011-02-08 | 2026-04-29 |
| CVE-2010-1732 json | Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remot... | Not Provided | 2010-05-06 | 2026-04-29 |
| CVE-2010-1724 json | Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote... | Not Provided | 2010-05-06 | 2026-04-29 |
Known software with vulnerabilities from Zikula
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Zikula | Zikula Application Framework | 1.3.0 |