Home/Product/juzaweb cms
Product

juzaweb cms

39 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-67443
< 2.2.9-5
Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form,
6.1MEDIUM
CVE-2025-6736
all versions
A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality
6.3MEDIUM
CVE-2025-6735
all versions
A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/
6.3MEDIUM
CVE-2025-5429
>= 3.4 and <= 3.4.2
A vulnerability classified as critical was found in juzaweb CMS up to 3.4.2. This vulnerability affects unknown code of the file /
6.3MEDIUM
CVE-2025-5428
>= 3.4 and <= 3.4.2
A vulnerability classified as critical has been found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-
6.3MEDIUM
CVE-2025-5427
>= 3.4 and <= 3.4.2
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been rated as critical. Affected by this issue is some unknown functi
6.3MEDIUM
CVE-2025-5426
>= 3.4 and <= 3.4.2
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been declared as critical. Affected by this vulnerability is an unkno
6.3MEDIUM
CVE-2025-5425
>= 3.4 and <= 3.4.2
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as critical. Affected is an unknown function of the f
6.3MEDIUM
CVE-2025-5424
>= 3.4 and <= 3.4.2
A vulnerability was found in juzaweb CMS up to 3.4.2 and classified as critical. This issue affects some unknown processing of the
6.3MEDIUM
CVE-2025-5423
>= 3.4 and <= 3.4.2
A vulnerability has been found in juzaweb CMS up to 3.4.2 and classified as critical. This vulnerability affects unknown code of t
6.3MEDIUM
CVE-2025-5422
>= 3.4 and <= 3.4.2
A vulnerability, which was classified as problematic, was found in juzaweb CMS up to 3.4.2. This affects an unknown part of the fi
4.3MEDIUM
CVE-2025-5421
>= 3.4 and <= 3.4.2
A vulnerability, which was classified as critical, has been found in juzaweb CMS up to 3.4.2. Affected by this issue is some unkno
6.3MEDIUM
CVE-2025-5420
>= 3.4 and <= 3.4.2
A vulnerability classified as problematic was found in juzaweb CMS up to 3.4.2. Affected by this vulnerability is an unknown funct
3.5LOW
CVE-2024-7551
<= 3.4.2
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of th
2.7LOW
CVE-2023-31505
all versions
An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and
7.2HIGH
CVE-2023-46906
<= 3.4
juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The pay
4.9MEDIUM
CVE-2023-46467
<= 3.4
Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted
5.4MEDIUM
CVE-2023-34917
all versions
Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.
6.1MEDIUM
CVE-2023-34916
all versions
Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java.
6.1MEDIUM
CVE-2022-45544
all versions
Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbit
8.8HIGH
CVE-2019-11021
all versions
admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE
7.2HIGH
CVE-2019-11198
<= 9.0.1
Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary w
6.1MEDIUM
CVE-2019-9875
<= 9.1
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbi
8.8HIGH
CVE-2019-9874
>= 7.0 and <= 7.2
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore
9.8CRITICAL
CVE-2017-11440
all versions
In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScrat
4.9MEDIUM
CVE-2017-11439
all versions
In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.
5.4MEDIUM
CVE-2014-100004
<= 7.0
Cross-site scripting (XSS) vulnerability in Sitecore CMS before 7.0 Update-4 (rev. 140120) allows remote attackers to inject arbit
CVE-2012-5919
<= 1.0.4
Multiple cross-site scripting (XSS) vulnerabilities in Havalite 1.0.4 and earlier allow remote attackers to inject arbitrary web s
CVE-2012-5894
<= 1.1.0
SQL injection vulnerability in hava_post.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary SQL co
CVE-2012-5893
<= 1.1.0
Unrestricted file upload vulnerability in hava_upload.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arb
CVE-2012-5892
<= 1.1.0
Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remo
CVE-2012-4405
all versions
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as us
CVE-2009-3118
<= 0.5.2
SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to
CVE-2009-2163
<= 6.0.2
Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remote attacker
CVE-2009-1055
all versions
Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to
CVE-2009-0584
<= 1.0.3
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll
CVE-2008-2843
<= 2.50
Multiple SQL injection vulnerabilities in doITLive CMS 2.50 and earlier allow remote attackers to execute arbitrary SQL commands v
CVE-2008-2842
<= 2.50
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers to inject
CVE-2008-1513
<= 0.5.1
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled, allows r
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin